The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability.
References
Configurations
No configuration.
History
19 Sep 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-19 13:15
Updated : 2025-09-19 16:00
NVD link : CVE-2025-7665
Mitre link : CVE-2025-7665
CVE.ORG link : CVE-2025-7665
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization