CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Miniorange 1Otp Verification With Firebase Jan 28, 2025 Oct 17, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to ob...Show more |
1Miniorange 1Otp Verification With Firebase Jan 28, 2025 Oct 17, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the...Show more |