Miniorange OTP Verification with Firebase <= 3.6.0 - Privilege Escalation via Registration due to Administrator Default User Role Value

2024-10-16 00:00
István Márton

Strategic Overview

Status
Patched in 3.6.1
Affected Version<= 3.6.0
CVSS9.8Critical
CVECVE-2024-9863
View all Miniorange OTP Verification with Firebase vulnerabilities

Vulnerability Overview

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.

Technical Analysis

REMEDIATION: Update to version 3.6.1, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C