CVE-2025-7665

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability.
Configurations

No configuration.

History

19 Sep 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-19 13:15

Updated : 2025-09-19 16:00


NVD link : CVE-2025-7665

Mitre link : CVE-2025-7665

CVE.ORG link : CVE-2025-7665


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization