CVE-2025-9967

CRITICAL

Orion SMS OTP Verification <1.1.7 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-9967. PoCs published by jFriedli.

AI-analyzed exploit summary This repository contains a functional JavaScript exploit for CVE-2025-9967, demonstrating an unauthenticated OTP password reset vulnerability in WordPress. The PoC extracts a nonce and AJAX URL from the target site, then sends a crafted request to reset a victim's password via OTP, revealing the new password in the response.

Description

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's password to a one-time password if the attacker knows the user's phone number

Exploits (1)

nomisec WORKING POC
by jFriedli · poc
https://github.com/jFriedli/CVE-2025-9967

This repository contains a functional JavaScript exploit for CVE-2025-9967, demonstrating an unauthenticated OTP password reset vulnerability in WordPress. The PoC extracts a nonce and AJAX URL from the target site, then sends a crafted request to reset a victim's password via OTP, revealing the new password in the response.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WordPress (version not specified)
No auth needed
Prerequisites: Access to the target WordPress site · Victim's phone number and country code
devstral-2 · analyzed Apr 28, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0039
EPSS Percentile 30.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-288
Status published
Products (2)
gsayed786/Orion SMS OTP Verification < 1.1.7
gsayed786/Orion SMS OTP Verification. < 1.1.7
Published Oct 15, 2025
Tracked Since Feb 18, 2026