CVE-2026-61967 CRITICAL

CVE-2026-61967: WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability

Vendor Miniorange
Product miniorange otp verification
Weakness CWE-640 · Weak password recovery
Published August 13, 2026
Last update August 13, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.

Explanation of Vulnerability in Simple Terms

02Summary

The miniOrange OTP Verification plugin through version 5.5.1 uses a weak password recovery mechanism that allows attackers to bypass authentication without credentials or user interaction. An attacker can gain full control of the site, including reading and modifying all data and disrupting service. This is a critical vulnerability affecting all installations.

What an attacker can do

03Attacker Capabilities

Bypass authentication and gain full control of the site without needing valid credentials.

Potential impact on your site

04Site Impact

Complete compromise: attackers can read all data, modify content, create admin accounts, and take the site offline.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 13, 2026 CVE published

Related vulnerabilities

08Related CVE