miniOrange OTP Login, Verification and SMS Notifications <= 5.5.7 - Unauthenticated Authentication Bypass via Login OTP Phone Number

Critical 9.8 CWE-287Fixed in 5.5.8
ID
WPSEC-2026-0719
Plugin
miniOrange OTP Login, Verification and SMS Notifications (miniorange-otp-verification)
Affected
all versions before 5.5.8
Remediation
Update to 5.5.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-287
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
miniOrange OTP Login, Verification and SMS Notifications on WPSec AttackSurface
Fix released
Published

Description

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the phone-based login OTP AJAX handler in all versions up to, and including, 5.5.7. This is due to the plugin sending the login OTP to a phone number supplied in the request instead of the phone number registered to the user bound to the login session. This makes it possible for unauthenticated attackers to receive a target user's login OTP on a phone they control, verify it, and log in as that user, including administrators.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0