Back to Labs
Security Advisory

CVE-2024-9861

About

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the phone number associated with that user.

Weakness (CWE):CWE-288CWE-306

Rainforest analyst review

The Miniorange OTP Verification with Firebase plugin fails to validate the token supplied during OTP login, so an unauthenticated attacker can log in as any existing user — including an administrator — provided they know the phone number tied to that account. The mechanism that's supposed to prove possession of a phone is effectively skipped, collapsing OTP login into 'name the phone number, get the account.'

Two things shape the real risk. On one hand, this is unauthenticated admin takeover on a WordPress plugin, which is severe; on the other, it's gated by knowing the target's phone number and rated as a difficult attack, so it's not a blind one-request smash against every install. That makes it most dangerous for accounts whose associated phone numbers are discoverable or guessable, and it leans toward targeted use over indiscriminate spraying.

We handle this with the usual WordPress inventory sweep, sharpened by the phone-number precondition. We map which sites run this plugin and at what version, and prioritize by whether high-value accounts' phone numbers are exposed anywhere an attacker could harvest them. Where we can't patch immediately, watching for anomalous OTP-login attempts against privileged accounts is a sensible interim detection, but the fix is getting affected sites past the vulnerable version quickly given that admin impersonation is the prize.

References

Related CVEs

Frequently asked questions

What is CVE-2024-9861?

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin.

How severe is CVE-2024-9861?

CVE-2024-9861 carries a CVSS 3.1 base score of 8.1, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 90 out of 100, in the critical band.

How is CVE-2024-9861 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity High, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2024-9861?

Public advisories list the following as affected: otp verification with firebase. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2024-9861?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email