Vulnerabilities / miniOrange OTP Login, Verification and SMS Notifications / WPSEC-2026-0719
miniOrange OTP Login, Verification and SMS Notifications <= 5.5.7 - Unauthenticated Authentication Bypass via Login OTP Phone Number
Critical 9.8
CWE-287Fixed in 5.5.8
- ID
- WPSEC-2026-0719
- Plugin
- miniOrange OTP Login, Verification and SMS Notifications (miniorange-otp-verification)
- Affected
- all versions before 5.5.8
- Remediation
- Update to 5.5.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-287
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- miniOrange OTP Login, Verification and SMS Notifications on WPSec AttackSurface
- Fix released
- Published
Description
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the phone-based login OTP AJAX handler in all versions up to, and including, 5.5.7. This is due to the plugin sending the login OTP to a phone number supplied in the request instead of the phone number registered to the user bound to the login session. This makes it possible for unauthenticated attackers to receive a target user's login OTP on a phone they control, verify it, and log in as that user, including administrators.
References
- https://wpsec.com/vuln/WPSEC-2026-0719/
- https://plugins.svn.wordpress.org/miniorange-otp-verification/tags/5.5.8/
- https://wordpress.org/plugins/miniorange-otp-verification/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS