The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Sep 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Miniorange
Miniorange otp Verification With Firebase Wordpress Wordpress wordpress |
|
Vendors & Products |
Miniorange
Miniorange otp Verification With Firebase Wordpress Wordpress wordpress |
Fri, 19 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 19 Sep 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability. | |
Title | Miniorange OTP Verification with Firebase 3.1.0 - 3.6.2 - Unauthenticated Privilege Escalation | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-09-19T12:27:36.481Z
Updated: 2025-09-19T13:05:05.787Z
Reserved: 2025-07-14T21:34:58.243Z
Link: CVE-2025-7665

Updated: 2025-09-19T13:05:02.376Z

Status : Awaiting Analysis
Published: 2025-09-19T13:15:43.973
Modified: 2025-09-19T16:00:27.847
Link: CVE-2025-7665

No data.