Miniorange OTP Verification with Firebase 3.1.0 - 3.6.2 - Unauthenticated Privilege Escalation

2025-09-19 00:13
kr0d

Strategic Overview

Status
Patched in 3.6.3
Affected Version3.1.0 – 3.6.2
CVSS8.1High
CVECVE-2025-7665
View all Miniorange OTP Verification with Firebase vulnerabilities

Vulnerability Overview

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability.

Technical Analysis

REMEDIATION: Update to version 3.6.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C