Skip to content
Noroxi

miniOrange 2FA – Two-Factor Authentication for WordPress (SMS, Email & Google Authenticator)

miniorange-2-factor-authentication · plugin

Known security vulnerabilities for miniOrange 2FA – Two-Factor Authentication for WordPress (SMS, Email & Google Authenticator). Find out in seconds which version runs on your site with WP Lens.

4 known vulnerabilities

latest Dec 18, 2025

Vulnerabilities

  • CVE-2022-42461

    WordPress miniOrange's Google Authenticator plugin <= 5.6.1 - Broken Access Control vulnerability

    High 8.8
  • CVE-2022-44589

    WordPress miniOrange's Google Authenticator Plugin <= 5.6.1 is vulnerable to Sensitive Data Exposure

    High 7.5
  • CVE-2025-54745

    WordPress miniOrange's Google Authenticator Plugin <= 6.1.1 - Broken Access Control Vulnerability

    Medium 6.5
  • CVE-2022-4943

    miniOrange's Google Authenticator <= 5.6.5 - Missing Authorization to Plugin Settings Change

    Medium 5.3

← Back to directory