← WordPress Vulnerabilities
WordPress security by component

miniOrange OTP Verification and SMS Notification for WooCommerce

miniOrange OTP Verification and SMS Notification for WooCommerce is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jan 10, 2026; the highest CVE/CNA score is 5.3.

Plugin slug: miniorange-sms-order-notification-otp-verification

CVE-2025-14948: miniOrange OTP Verification and SMS Notification for WooCommerce: A security weakness

miniOrange OTP Verification and SMS Notification for WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJan 10, 2026
Safe version guidanceSee mitigation notes
Safe version
Jan 10, 2026 CVE-2025-14948
miniOrange OTP Verification and SMS Notification for WooCommerce: A security weakness
miniOrange OTP Verification and SMS Notification for WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending