5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `enable_wc_sms_notification` AJAX action in all versions up to, and including, 4.3.8. This makes it possible for unauthenticated attackers to enable or disable SMS notification settings for WooCommerce orders.
Basic Information
ID
CVE-2025-14948
Source
Wordfence
Published
Jan 10, 2026 at 07:03
Affected Product
Vendor
cyberlord92
Product
miniOrange OTP Verification and SMS Notification for WooCommerce
Version
*
Affected Versions
cyberlord92 miniOrange OTP Verification and SMS Notification for WooCommerce *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/f84ddc83-2079-45b9-8354-51094581b1f8
- plugins.trac.wordpress.org /browser/miniorange-sms-order-notification-otp-verification/tags/4.3.8/notifications/wcsmsnotification/handler/class-woocommercenotifications.php
- plugins.trac.wordpress.org /browser/miniorange-sms-order-notification-otp-verification