Extension WordPress
Vulnérabilités Miniorange OTP Verification with Firebase
Cette page rassemble les failles publiées pour Miniorange OTP Verification with Firebase, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Miniorange OTP Verification with Firebase
4 fiches
Miniorange OTP Verification with Firebase 3.1.0 – 3.6.2 – Unauthenticated Privilege Escalation
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update…
3.1.0-3.6.2
3.6.3
19/09/2025
Miniorange OTP Verification with Firebase <= 3.6.0 – Privilege Escalation via Registration due to Administrator Default User Role Value
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated…
*-3.6.0
3.6.1
16/10/2024
Miniorange OTP Verification with Firebase <= 3.6.0 – Unauthenticated Arbitrary User Password Change
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass…
*-3.6.0
3.6.1
16/10/2024
Miniorange OTP Verification with Firebase <= 3.6.0 – Authentication Bypass
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the…
*-3.6.0
3.6.1
16/10/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.