Junglewise Threat Intelligence

CVE-2026-42731: miniOrange OTP Verification privilege escalation

CVE-2026-42731 · Severity: critical · CVSS 9.8 · Published 2026-05-27

Vendors: miniOrange.

Executive brief

The miniOrange OTP Verification plugin for WordPress, which provides one-time password security for logins and forms, contains a critical flaw in how it manages user permissions. An unauthorized attacker can exploit this weakness to gain administrative control over the website. This could lead to full site takeover, theft of customer data, or the installation of malicious software.

Technical details

An Incorrect Privilege Assignment vulnerability (CWE-266) exists in the miniOrange OTP Verification plugin for WordPress through version 5.4.9. The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining administrative access to the WordPress site. The vulnerability stems from improper validation or assignment of user roles during the authentication or verification process. With a CVSS score of 9.8, the exploit requires no user interaction and can be executed over the network with low complexity. Users are advised to update to version 5.5.0 or later to remediate the issue.

Affected products

  • miniOrange OTP Verification <= 5.4.9

Timeline

  • 2026-04-24: other: Reported by Peng Zhou
  • 2026-05-24: advisory: Patchstack advisory published
  • 2026-05-27: disclosed: CVE published to NVD

References

Related threats