miniOrange 2FA for WordPress versions before 6.3.1 on the 6.x release line and before 19.3 on the 19.x release line fail to validate a transaction before deleting WordPress site options. An unauthenticated request can supply the name of an option to delete, permitting arbitrary deletion of site options without authorization.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains an MIT license, usage documentation, and one standalone Python 3 exploit script using only the standard library. It targets CVE-2026-77770 in the miniOrange 2-Factor Authentication WordPress plugin through its email-verification flow. The script creates a cookie-aware HTTP session, supports redirects and TLS verification bypass, retries connection behavior through its URL handling, fingerprints the plugin from its readme.txt, checks for handler response markers, and queries the WordPress REST API for publicly exposed site identity data. In --test mode it performs non-destructive plugin/handler checks. In --delete mode it sends a crafted root-path GET request that can delete a specified wp_options row when a selected transaction-gate option currently holds integer value 3. Default gate candidates are wp_page_for_privacy_policy and thread_comments_depth. The documented proof case deletes blogname and verifies the public site title via /wp-json/. The exploit is operational rather than framework-based: its target URL, option to delete, gates, timeout, and TLS behavior are configurable, but it implements one narrowly scoped HTTP attack path.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.