WordPress 插件 miniOrange OTP Login、Verification and SMS Notifications 在 5.5.5 及更早版本中存在漏洞,可通过 参数实现认证绕过。该漏洞的成因是:在启用 配置的代码分支中, 函数缺少对 password-intent 的检查机制。当提交未经认证和验证的 POST 参数 且其值为 时,该函数仅凭用户是否具有管理员角色就判定认证通过,导致 跳过标准的 函数,仅根据用户名进行查询并构建 WP_User 对象。因此,攻击者只需提供已知的管理员用户名和空
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cyberlord92 | miniOrange OTP Login, Verification and SMS Notifications | ≤ 5.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cyberlord92 | miniOrange OTP Login, Verification and SMS Notifications | 0 ~ 5.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet