CVE-2026-85984 is an improper-authentication vulnerability in the miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress through version 5.5.5. In the skip_pass_fallback-enabled branch of the mo_by_pass_login() function, a missing password-intent guard allows an unauthenticated login request marked as an OTP login to resolve a user account by username without invoking WordPress password authentication or completing OTP validation. When the affected configuration is enabled, an attacker can authenticate as an existing administrator by supplying a known administrator username and an empty password.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository is a standalone Python 3 exploit PoC for CVE-2026-85984 affecting the miniOrange OTP Login, Verification and SMS Notifications WordPress plugin through version 5.5.5. Its main entry point, `poc.py` (about 22 KB), uses `requests` and `urllib3` to scan target sites, identify the plugin/version, optionally probe login behavior, enumerate likely WordPress usernames through REST and author mechanisms, and attempt an administrator login bypass. The exploit request targets `wp-login.php` with `mo_wp_login_intent=otp`, an administrator username, and an empty password. It supports individual URLs or target lists, concurrency, proxies, disabled TLS verification, colored output, JSONL reporting, and separate vulnerable/exploited target lists. `README.md` documents the affected configuration, usage, FOFA fingerprints, and the claimed fixed version; `targets.example.txt` supplies sample targets; and `requirements.txt` lists the two Python HTTP dependencies. This is an active exploitation tool rather than a detection-only script because exploit mode attempts to establish an authenticated administrator session.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication-bypass vulnerability in the miniOrange OTP Login, Verification and SMS Notifications WordPress plugin through version 5.5.5. A missing password-intent guard in the skip_pass_fallback branch allows an unauthenticated user to authenticate as an administrator by submitting mo_wp_login_intent=otp with a known administrator username and an empty password, provided the affected site has enabled the required OTP and Admin OTP Bypass options.
Critical unauthenticated authentication-bypass vulnerability (CWE-287) in the miniOrange OTP Login, Verification and SMS Notifications WordPress plugin through version 5.5.5. A missing password-intent check in mo_by_pass_login() can allow authentication as an administrator without a password or OTP under a conditional, insecure plugin configuration.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.