


Perceptive Security
SOC/SIEM Consultancy

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeov…
Published:
8 juli 2026 om 22:00:00
Alert date:
9 juli 2026 om 09:01:00
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
CVE-2026-14245 is a critical authentication bypass vulnerability in the miniOrange OTP Login, Verification and SMS Notifications WordPress plugin affecting all versions up to and including 5.5.1. The flaw exists in the `um_reset_password_process_hook()` function, which performs no server-side verification that an OTP validation step was completed. The plugin exposes a public `form_nonce` nonce to unauthenticated visitors and accepts an attacker-controlled `username_b` parameter, allowing targeting of any WordPress user including administrators. An unauthenticated attacker can obtain a freshly generated password-reset URL for any administrator account via a 302 Location header redirect, leading to full account takeover. Exploitation requires the Ultimate Member Password Reset Form integration to be active and the plugin not configured for phone-only reset. No authentication or prior session binding is required to exploit this vulnerability.
Technical details
Mitigation steps:
Affected products:
miniOrange OTP Login Verification and SMS Notifications WordPress plugin (up to 5.5.1)
Ultimate Member Password Reset Form integration
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14245
https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.0/handler/forms/class-moumpasswordreset.php#L181
https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.0/handler/forms/class-moumpasswordreset.php#L367
https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.0/handler/forms/class-moumpasswordreset.php#L372
https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.0/handler/forms/class-moumpasswordreset.php#L98
https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.1/handler/forms/class-moumpasswordreset.php#L181
https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.1/handler/forms/class-moumpasswordreset.php#L367
https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.1/handler/forms/class-moumpasswordreset.php#L372
https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.1/handler/forms/class-moumpasswordreset.php#L98
https://plugins.trac.wordpress.org/changeset?reponame=&old=3595061%40miniorange-otp-verification&new=3595061%40miniorange-otp-verification
https://www.wordfence.com/threat-intel/vulnerabilities/id/d34f4e77-f384-4d84-be32-0d349962b614?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
