Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-106610: miniOrange OTP plugin lets users gain admin rights

CVE-2026-106610 · published today
Summary

The miniOrange OTP Verification plugin for WordPress (up to version 5.5.7) can incorrectly grant higher privileges than intended. This could allow a regular user or attacker to obtain administrator-level access to the site. Update the plugin to the latest version or remove it if you cannot apply the fix.

What to do
  • Update miniorange miniorange otp verification to version 5.5.8.
Affected software
VendorProductAffected versions
miniorange miniorange otp verification <= 5.5.7
Fix: upgrade to 5.5.8
Original advisory text
WordPress miniorange otp verification plugin <= 5.5.7 - Privilege Escalation vulnerability
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically (estimated)
  • Gives an attacker full control (estimated)
Severity
9.8 Critical
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published10 Oct 2026
Updated10 Oct 2026
First seen10 Oct 2026
Sources
CVE-2026-106610 · MITRE
Track software like this
Free during beta