Impact
The miniorange OTP Verification plugin contains an unauthenticated Cross‑Site Scripting vulnerability, allowing an attacker to inject malicious client‑side scripts into pages served by the plugin. The weakness aligns with CWE‑79 and can alter the content presented to users. No other impacts such as credential theft or session hijacking are stated in the CVE data.
Affected Systems
WordPress sites that have the miniOrange OTP Verification plugin version 5.5.1 or earlier. Upgrading to version 5.5.2 or later eliminates the flaw.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity issue. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Attackers can exploit the flaw without authentication, most likely by delivering a crafted URL or form that the plugin fails to sanitize, causing arbitrary script execution in the victim's browser.
OpenCVE Enrichment