PT-2025-38531 · WordPress · Miniorange Otp Verification With Firebase

Kenneth Dunn

·

Published

2025-09-19

·

Updated

2025-09-19

·

CVE-2025-7665

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Miniorange OTP Verification with Firebase plugin for WordPress versions 3.1.0 through 3.6.2
Description The Miniorange OTP Verification with Firebase plugin for WordPress is susceptible to privilege escalation. A missing capability check on the handle mofirebase form options function allows unauthenticated attackers to update the default role to Administrator. Exploitation requires premium features to be enabled.
Recommendations Update to a version beyond 3.6.2.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-7665

Affected Products

Miniorange Otp Verification With Firebase