PT-2026-56720 · WordPress+1 · Miniorange Otp Login+1

·

CVE-2026-14245

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions miniOrange OTP Login, Verification and SMS Notifications versions prior to 5.5.2
Description An authentication bypass exists that allows for administrator account takeover. The issue occurs because the um reset password process hook() function fails to perform server-side verification to ensure the OTP validation step was completed. Instead, it relies on a public form nonce nonce emitted to unauthenticated visitors via the moumprvar JavaScript object on the Ultimate Member password reset page. An unauthenticated attacker can provide a controlled username b parameter to target any WordPress user, regardless of role, without a validated OTP session. This allows the attacker to obtain a password-reset URL in a 302 Location header and gain full control of the account. This requires the Ultimate Member Password Reset Form integration to be active and the plugin to not be configured for phone-only reset.
Recommendations Update the plugin to a version newer than 5.5.1. As a temporary mitigation, disable the Ultimate Member Password Reset Form integration or configure the plugin for phone-only reset.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14245

Affected Products

Ultimate Member
Miniorange Otp Login