cleantalk
Vulnerabilities and Security Researches

Email Verification / SMS Verification / OTP Verification / OTP Authentication / WooCommerce Notification, 621f296b6870e58890ecf2cecbb450d88fff0326

Published on
Nov 14, 2023
Research Description
Email Verification / SMS Verification / OTP Verification / OTP Authentication / WooCommerce Notification [miniorange-otp-verification] < 4.2.2 WordPress miniorange otp verification Plugin <= 4.2.1 is vulnerable to Broken Access Control Update the WordPress miniorange otp verification plugin to the latest available version (at least 4.2.2). Abdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress miniorange otp verification Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 4.2.2.
Affected versions
max 4.2.2.
Status
vulnerable