Impact
The vulnerability in the miniorange OTP Verification plugin resides in its insufficient access control, allowing an unauthenticated user to trigger a privileged action within the WordPress site. By exploiting this flaw, an attacker can obtain higher privileges than intended, potentially gaining administrative rights or controlling site content. The core weakness is identified as CWE‑640, which governs inappropriate authorization checks. Without remediation, the attacker can alter site configuration, create new admin accounts, or modify existing data, compromising confidentiality, integrity, and availability of the WordPress environment.
Affected Systems
WordPress installations running the miniorange OTP Verification plugin version 5.5.1 or earlier are affected. The vulnerability is cataloged by the CNA under miniOrange:miniorange otp verification, and all such deployments lacking an update to 5.5.2 or later are exposed. No specific CPE strings are provided, so all sites with the vulnerable plugin version are at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the lack of an EPSS value means the risk of exploitation in the near term is unknown but could still be high. The vulnerability remains unreported in CISA KEV, but its unauthenticated nature makes it attractive to attackers looking for low‑effort exploitation. The attack is most likely carried out remotely via web requests that leverage the plugin’s oversight in access control, bypassing authentication entirely.
OpenCVE Enrichment