Missing Authorization in miniOrange's Google Authenticator Plugin
CVE-2025-54745

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 December 2025

What is CVE-2025-54745?

The miniOrange 2-Factor Authentication plugin for WordPress is susceptible to a missing authorization issue that arises from incorrectly configured access control security levels. This vulnerability permits unauthorized users to exploit access controls, potentially allowing them to bypass authentication mechanisms. It affects all versions of the plugin up to and including 6.1.1. Website administrators using this plugin should ensure that proper access controls are configured to mitigate risks associated with unauthorized access.

Affected Version(s)

miniOrange's Google Authenticator 0 <= 6.1.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.