Privilege Escalation Flaw in miniOrange OTP Verification Plugin
CVE-2026-106610

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-106610?

A vulnerability exists in the miniOrange OTP Verification plugin that allows for incorrect privilege assignments. This security flaw could enable unauthorized users to escalate their privileges, potentially gaining access to functionalities reserved for higher-privileged users. The issue affects versions from n/a through 5.5.7, posing a significant risk to sites using this plugin.

Affected Version(s)

miniorange otp verification 0 <= 5.5.7

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KevineCharles | Patchstack Bug Bounty Program
.