CVE 8.1 HIGH

Miniorange OTP Verification with Firebase 3.1.0 – 3.6.2 – Unauthenticated Privilege Escalation_CVE-2025-7665

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability.

Basic Information

ID CVE-2025-7665
Source Wordfence
Published Sep 19, 2025 at 12:27

Affected Product

Vendor cyberlord92
Product Miniorange OTP Verification with Firebase
Version 3.1.0
Affected Versions cyberlord92 Miniorange OTP Verification with Firebase 3.1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.