plugin

Miniorange Firebase Sms Otp Verification Vulnerabilities

8 known security issues reported for the Miniorange Firebase Sms Otp Verification WordPress plugin. Most recent disclosed Sep 19, 2025.

2 critical 2 high

Running Miniorange Firebase Sms Otp Verification on your site? Check whether your installed version is affected.

Scan your site free

Miniorange OTP Verification with Firebase 3.1.0 - 3.6.2 - Unauthenticated Privilege Escalation

high

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premiu...

CVSS:
8.1
Affected:
3.1.0 – 3.6.2
Fixed in:
3.6.3
Disclosed:
Sep 19, 2025

CVE-2025-7665 on NVD →

Miniorange OTP Verification with Firebase [miniorange-firebase-sms-otp-verification] < 3.6.1 (closed)

unknown

[en] The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form i...

Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
Oct 17, 2024

CVE-2024-9863 on NVD →

Miniorange OTP Verification with Firebase [miniorange-firebase-sms-otp-verification] < 3.6.1 (closed)

unknown

[en] The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources, and the user current pa...

Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
Oct 17, 2024

CVE-2024-9862 on NVD →

Miniorange OTP Verification with Firebase [miniorange-firebase-sms-otp-verification] < 3.6.1 (closed)

unknown

[en] The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. This makes it possible for unauthenticated attackers to log in as...

Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
Oct 17, 2024

CVE-2024-9861 on NVD →

Miniorange OTP Verification with Firebase <= 3.6.0 - Unauthenticated Arbitrary User Password Change

critical

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources, and the user current passwor...

CVSS:
9.8
Affected:
up to 3.6.0
Fixed in:
3.6.1
Disclosed:
Oct 16, 2024

CVE-2024-9862 on NVD →

Miniorange OTP Verification with Firebase <= 3.6.0 - Privilege Escalation via Registration due to Administrator Default User Role Value

critical

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user ev...

CVSS:
9.8
Affected:
up to 3.6.0
Fixed in:
3.6.1
Disclosed:
Oct 16, 2024

CVE-2024-9863 on NVD →

Miniorange OTP Verification with Firebase <= 3.6.0 - Authentication Bypass

high

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. This makes it possible for unauthenticated attackers to log in as any...

CVSS:
8.1
Affected:
up to 3.6.0
Fixed in:
3.6.1
Disclosed:
Oct 16, 2024

CVE-2024-9861 on NVD →

Miniorange OTP Verification with Firebase [miniorange-firebase-sms-otp-verification] >= 3.1.0 - <= 3.6.2

unknown
Affected:
3.1.0 – 3.6.2
Fixed in:
3.6.2

CVE-2025-7665 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database