


Perceptive Security
SOC/SIEM Consultancy

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affect…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 15:06:57
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-42731 is an Incorrect Privilege Assignment vulnerability in the miniOrange OTP Verification WordPress plugin that allows privilege escalation. The vulnerability affects all versions from n/a through 5.4.9 and below. This type of vulnerability can allow attackers to gain elevated privileges within the affected system, potentially leading to unauthorized access and control. The issue is classified as high severity and affects a widely-used WordPress plugin for OTP verification functionality.
Technical details
Mitigation steps:
Affected products:
miniOrange OTP Verification
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42731
https://patchstack.com/database/Wordpress/Plugin/miniorange-otp-verification/vulnerability/wordpress-miniorange-otp-verification-plugin-5-4-9-privilege-escalation-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
