plugin

Orion Sms Otp Verification Vulnerabilities

1 known security issue reported for the Orion Sms Otp Verification WordPress plugin. Most recent disclosed Oct 14, 2025.

1 critical

Running Orion Sms Otp Verification on your site? Check whether your installed version is affected.

Scan your site free

Orion SMS OTP Verification <= 1.1.7 - Authentication Bypass via Account Takeover

critical

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change...

CVSS:
9.8
Affected:
up to 1.1.7
Fixed in:
2.0.0
Disclosed:
Oct 14, 2025

CVE-2025-9967 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database