Access violation vulnerability in miniOrange OTP Verification and SMS Notification for WooCommerce 4.3.8

The miniOrange plugin for WordPress, which verifies OTP and sends SMS notifications for WooCommerce, has a security issue. This means that anyone can change the settings for SMS notifications without permission. The problem is present in all versions up to 4.3.8, allowing attackers without an account to turn on or off SMS notifications for WooCommerce orders.

Detected in:

miniOrange OTP Verification and SMS Notification for WooCommerce fixed vulnerable versions: >= * <= 4.3.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.