top of page
perceptive_background_267k.jpg

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeov…

Published:

8 juli 2026 om 22:00:00

Alert date:

9 juli 2026 om 09:01:00

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Zero-Day Vulnerabilities

CVE-2026-14245 is a critical authentication bypass vulnerability in the miniOrange OTP Login, Verification and SMS Notifications WordPress plugin affecting all versions up to and including 5.5.1. The flaw exists in the `um_reset_password_process_hook()` function, which performs no server-side verification that an OTP validation step was completed. The plugin exposes a public `form_nonce` nonce to unauthenticated visitors and accepts an attacker-controlled `username_b` parameter, allowing targeting of any WordPress user including administrators. An unauthenticated attacker can obtain a freshly generated password-reset URL for any administrator account via a 302 Location header redirect, leading to full account takeover. Exploitation requires the Ultimate Member Password Reset Form integration to be active and the plugin not configured for phone-only reset. No authentication or prior session binding is required to exploit this vulnerability.

Technical details

Mitigation steps:

Affected products:

miniOrange OTP Login Verification and SMS Notifications WordPress plugin (up to 5.5.1)
Ultimate Member Password Reset Form integration

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page