CVE-2026-61967

9.8

miniOrange · miniorange otp verification

An unauthenticated privilege escalation vulnerability in the miniOrange OTP Verification plugin for WordPress versions 5.5.1 and below allows attackers to gain unauthorized elevated access.

Executive summary

A critical privilege escalation vulnerability in the miniOrange OTP Verification WordPress plugin allows unauthenticated attackers to gain unauthorized administrative access to the site.

Vulnerability

The plugin suffers from a weak password recovery mechanism (CWE-640) that permits an unauthenticated attacker to escalate privileges. This flaw bypasses standard authentication controls, granting the attacker excessive permissions.

Business impact

An attacker successfully exploiting this vulnerability can obtain administrative control over the affected WordPress instance. This leads to total compromise, including the ability to exfiltrate sensitive data, modify site content, or install malicious backdoors. The CVSS score of 9.8 reflects the high severity of full system impact.

Remediation

Immediate Action: Update the miniOrange OTP Verification plugin to version 5.5.2 or later immediately.

Proactive Monitoring: Audit WordPress user logs for unauthorized account creation or unexpected elevation of user roles.

Compensating Controls: Ensure that WordPress administrative panels are not exposed to the public internet and utilize a Web Application Firewall (WAF) to filter malicious requests.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this privilege escalation flaw requires immediate remediation. All WordPress administrators should verify their plugin versions and ensure that the update to 5.5.2 is applied across all environments to prevent unauthorized access and potential site takeover.

More miniOrange CVEs