Authentication vulnerability in Miniorange OTP Verification with Firebase 3.6.0

A plugin called Miniorange OTP Verification with Firebase for WordPress has a security issue that allows people to bypass the login process. This happens because the plugin does not check the validity of the token used during the login. As a result, someone who is not logged in can pretend to be any registered user on the website, even an administrator. This can happen if the attacker knows the phone number of the user they want to impersonate.

Detected in:

Miniorange OTP Verification with Firebase open vulnerable versions: >= * <= 3.6.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.