{"schema_version":"1.0","report_url":"https://aretiq.ai/research/vul260815-cve-2026-61967-miniorange-otp-verification-ultimate-member-password-reset-authentication-bypass/","date":"2026-08-15","last_modified":"2026-08-15","cve":"CVE-2026-61967","title":"CVE-2026-61967 — miniOrange OTP Verification Ultimate Member Password Reset Authentication Bypass","vulnerability_name":"miniOrange OTP Verification Ultimate Member Password Reset Authentication Bypass","vendor":"miniOrange","product":"OTP Verification","component":"Ultimate Member Password Reset","binary":"class-moumpasswordreset.php","impact":"Auth Bypass","cwe":["CWE-640","CWE-306","CWE-287"],"severity":{"cvss_v4_score":8.2,"cvss_v4_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"},"attack_vector":"Network","patch_kb":"5.5.2","poc_verified":true,"poc_download":"https://aretiq.ai/downloads/","tags":["wordpress","otp-bypass","password-reset","authentication-bypass","privilege-escalation","ultimate-member"],"summary":"CVE-2026-61967 — miniOrange OTP Verification Ultimate Member Password Reset Authentication Bypass 1. Overview A vulnerability exists in the miniOrange OTP Verification plugin for WordPress (versions 5.5.1 and earlier) that allows an unauthenticated attacker to bypass OTP verification during the Ultimate Member password reset flow. The plugin’s um_reset_password_process_hook handler processes password reset requests without checking whether the required OTP was actually validated, relying solely on a publicly available WordPress nonce for authorization. An attacker can submit the password reset form for any user account, including administrators, and receive a valid password reset URL in the HTTP response, enabling full account takeover without any OTP or credential. The vendor addressed this vulnerability in version 5.5.2 by adding OTP session validation and username integrity checks.\n"}