Impact
The miniOrange OTP Login, Verification and SMS Notifications WordPress plugin is vulnerable to an authentication bypass that allows any unauthenticated user to trigger the password‑reset flow for any WordPress account without role restriction, including administrators. The flaw resides in the function that accepts the attacker‑controlled 'username_b' parameter and relies solely on a public form nonce that is exposed to unauthenticated visitors. As a result, an attacker can obtain a valid password‑reset URL for an administrator account, which redirects to a location header that grants full control over that account. This is a severe missing‑access‑control weakness (CWE‑862) with potential to compromise the entire site’s administrative security.
Affected Systems
The vulnerability affects all releases of the miniOrange OTP plugin up to and including version 5.5.1. It applies to the WordPress integration of the Ultimate Member Password Reset Form and requires the plugin not be configured for phone‑only reset. Administrators using this plugin on any WordPress installation are at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is under 1%, suggesting a relatively low estimated exploitation probability. The issue is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated user exploiting the public password reset form on the site, provided the Ultimate Member integration is active and phone‑only reset is not enforced.
OpenCVE Enrichment