CVE-2024-9862 is a critical arbitrary user password change vulnerability affecting the Miniorange OTP Verification with Firebase plugin for WordPress, versions 3.6.0 and earlier. This flaw allows unauthenticated attackers to bypass authorization and change any user's password, including administrator accounts, due to missing current password checks. With a CVSS score of 9.8, this vulnerability presents a severe risk of full system compromise. There is currently no public exploit code available, and it is not listed on the CISA KEV catalog, nor is there significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.1CPE matchmatch criteria | cpe:2.3:a:miniorange:otp_verification_with_firebase:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.