Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30292 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 22 Sep 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Miniorange
Miniorange otp Verification With Firebase Wordpress Wordpress wordpress |
|
| Vendors & Products |
Miniorange
Miniorange otp Verification With Firebase Wordpress Wordpress wordpress |
Fri, 19 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability. | |
| Title | Miniorange OTP Verification with Firebase 3.1.0 - 3.6.2 - Unauthenticated Privilege Escalation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-09-19T13:05:05.787Z
Reserved: 2025-07-14T21:34:58.243Z
Link: CVE-2025-7665
Updated: 2025-09-19T13:05:02.376Z
Status : Awaiting Analysis
Published: 2025-09-19T13:15:43.973
Modified: 2025-09-19T16:00:27.847
Link: CVE-2025-7665
No data.
OpenCVE Enrichment
Updated: 2025-09-22T10:06:26Z
EUVD