Description
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.
Problem types
CWE-266 Incorrect Privilege Assignment
Product status
Any version
Timeline
| 2024-10-11: | Discovered |
| 2024-10-11: | Vendor Notified |
| 2024-10-16: | Disclosed |
Credits
István Márton
References
www.wordfence.com/...-dd86-4145-b5eb-20d064bc8417?source=cve
plugins.trac.wordpress.org/...rms/class-registrationform.php
plugins.trac.wordpress.org/...-firebase-sms-otp-verification