Showing 1 vulnerability on this page for miniOrange OTP Login, Verification and SMS Notifications

Signals CISA KEV Ransomware Nuclei
cyberlord92 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 - Authentication Bypass to Administrator Account Takeover via 'username_b' Parameter

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the OTP validation step was completed, and relying solely on a public `form_nonce` nonce that the plugin itself emits to unauthenticated visitors via the `moumprvar` JavaScript object o

CWE-862Jul 9, 2026
CVSS9.8v3.1EPSS0.586%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX