Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-106610: miniOrange OTP plugin lets users gain admin rights
CVE-2026-106610 · published today
Summary
The miniOrange OTP Verification plugin for WordPress (up to version 5.5.7) can incorrectly grant higher privileges than intended. This could allow a regular user or attacker to obtain administrator-level access to the site. Update the plugin to the latest version or remove it if you cannot apply the fix.
What to do
- Update miniorange miniorange otp verification to version 5.5.8.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| miniorange | miniorange otp verification |
<= 5.5.7 Fix: upgrade to 5.5.8
|
Original advisory text
WordPress miniorange otp verification plugin <= 5.5.7 - Privilege Escalation vulnerability
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.
References
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically (estimated)
- Gives an attacker full control (estimated)
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published10 Oct 2026
Updated10 Oct 2026
First seen10 Oct 2026
Track software like this
Free during beta