CVE-2026-61967 — miniOrange OTP 验证 Ultimate Member 密码重置认证绕过
aretiq.ai | 研究 | CVE-2026-61967 | #ai-security | #authentication-bypass | #wordpress | #authentication | #vulnerability | #cve | #password-reset | #miniorange | #cve-2026-61967 | #otp
摘要
Aretiq 分析 CVE-2026-61967:WordPress 插件 miniOrange OTP Verification(5.5.1 及更早)在 Ultimate Member 密码重置流程中不校验 OTP,未认证攻击者可凭公开 nonce 获取任意账户(含管理员)的重置链接,实现完全接管。
为什么值得关注
这项研究提供技术背景,便于安全团队开展监测和验证。
- 厂商
- miniOrange
- 产品
- OTP Verification plugin for WordPress
- 受影响版本
- 5.5.1 and earlier; fixed in 5.5.2
- 发布时间
- 收录时间
Skip to content