CVE-2026-61967 — miniOrange OTP Verification Ultimate Member Password Reset Authentication Bypass
aretiq.ai | research | CVE-2026-61967 | #ai-security | #authentication-bypass | #wordpress | #authentication | #vulnerability | #cve | #password-reset | #miniorange | #cve-2026-61967 | #otp
Summary
Aretiq analyzes CVE-2026-61967: miniOrange's OTP Verification plugin (≤5.5.1) skips OTP checks in Ultimate Member's password reset, letting unauthenticated attackers reset any account's password.
Why it matters
This research provides technical context that security teams can use for monitoring and validation.
- Vendor
- miniOrange
- Product
- OTP Verification plugin for WordPress
- Affected versions
- 5.5.1 and earlier; fixed in 5.5.2
- Published
- Collected
Skip to content