miniOrange OTP Login, Verification and SMS Notifications
- <= 5.5.1
A vulnerability exists in the miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress, affecting all versions up to and including 5.5.1. The issue arises from the 'um_reset_password_process_hook()' function, which fails to perform server-side verification of OTP validation. Instead, it relies on a public 'form_nonce' that the plugin sends to unauthenticated users via the 'moumprvar' JavaScript object on the Ultimate Member password reset page. The function also accepts the 'username_b' parameter, allowing attackers to target any WordPress user without role restrictions or a validated OTP session. This flaw enables unauthenticated attackers to generate a password-reset URL for any Administrator account, which can be used to gain full control of that account. Exploitation requires the Ultimate Member Password Reset Form integration to be active and the plugin not to be set for phone-only resets.
Exploitation of this vulnerability allows for authentication bypass, enabling unauthorized users to gain administrative privileges and take over administrator accounts.
To reproduce this vulnerability, first ensure that the miniOrange OTP Login, Verification and SMS Notifications plugin is installed and activated on a WordPress site, along with the Ultimate Member plugin. The vulnerability can be exploited by sending a request to the WordPress site with the 'username_b' parameter set to the username of an administrator account. The request must include a valid 'form_nonce' nonce, which can be obtained from the 'moumprvar' JavaScript object on the Ultimate Member password reset page. Once the request is processed, a password-reset URL for the targeted administrator account will be returned in a 302 'Location' header, allowing the attacker to reset the password and gain access to the account.
Users are advised to update the miniOrange OTP Login, Verification and SMS Notifications plugin to version 5.5.2 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.