CVE-2026-61967: WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability
Published Aug 13, 2026
·Updated
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
Affected Software
1 affected component
miniOrange OTP Verification<=5.5.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress miniorange otp verification Pluginto a version that resolves this vulnerability.Fixed in 5.5.2
Event History
Aug 13, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-61967?
CVE-2026-61967 has a critical severity rating of 9.8.
2
How does CVE-2026-61967 affect WordPress users?
CVE-2026-61967 allows unauthenticated users to escalate privileges within WordPress sites using the miniorange otp verification plugin.
3
What versions of the plugin are affected by CVE-2026-61967?
CVE-2026-61967 affects miniorange otp verification plugin versions up to and including 5.5.1.
4
What steps should be taken to mitigate CVE-2026-61967?
To mitigate CVE-2026-61967, update the miniorange otp verification plugin to the latest version.
5
Is CVE-2026-61967 exploitable remotely?
Yes, CVE-2026-61967 is exploitable remotely as it allows unauthenticated access to escalate privileges.