CVE-2025-54745: WordPress miniOrange's Google Authenticator Plugin <= 6.1.1 - Broken Access Control Vulnerability
Missing Authorization vulnerability in miniOrange miniOrange's Google Authenticator miniorange-2-factor-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects miniOrange's Google Authenticator: from n/a through <= 6.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54745?
CVE-2025-54745 has been classified as a critical severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-54745?
To fix CVE-2025-54745, update the miniOrange Google Authenticator to version 6.1.2 or later, which addresses the access control issue.
What software is affected by CVE-2025-54745?
CVE-2025-54745 affects miniOrange Google Authenticator and miniOrange Google Authenticator Plugin versions up to and including 6.1.1.
What kind of vulnerability is CVE-2025-54745?
CVE-2025-54745 is a missing authorization vulnerability that allows for exploitation of incorrectly configured access control security levels.
Can I still use miniOrange Google Authenticator if I have CVE-2025-54745?
It is highly recommended to not use miniOrange Google Authenticator until you have updated to a secure version to mitigate the risk associated with CVE-2025-54745.