CVE-2026-106610: WordPress miniorange otp verification plugin <= 5.5.7 - Privilege Escalation vulnerability
Published Oct 10, 2026
·Updated
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.
Affected Software
1 affected component
miniOrange OTP Verification<=5.5.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress miniorange otp verification pluginto a version that resolves this vulnerability.Fixed in 5.5.8
Event History
Oct 10, 2026
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects miniOrange OTP Verification versions through 5.5.7. The provided information does not identify any unaffected fixed version.
2
Does exploitation require authentication or user interaction?
The CVSS vector indicates network exploitation with low attack complexity, no privileges required, and no user interaction required. It also indicates potential impact to confidentiality, integrity, and availability.