CVE-2025-7665: Miniorange OTP Verification with Firebase 3.1.0 - 3.6.2 - Unauthenticated Privilege Escalation
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator. Premium features must be enabled in order to exploit the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7665?
CVE-2025-7665 has been classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-7665?
To fix CVE-2025-7665, update the Miniorange OTP Verification with Firebase plugin to the latest version where the vulnerability is patched.
Who is affected by CVE-2025-7665?
Any users running versions 3.1.0 to 3.6.2 of the Miniorange OTP Verification with Firebase plugin on WordPress are affected by CVE-2025-7665.
What type of vulnerability is CVE-2025-7665?
CVE-2025-7665 is a privilege escalation vulnerability that allows unauthenticated attackers to modify settings.
Is there a workaround for CVE-2025-7665?
Currently, there is no official workaround for CVE-2025-7665 other than updating to a secure version of the plugin.