<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Ultimate-Member on Aretiq AI</title><link>https://aretiq.ai/tags/ultimate-member/</link><description>Recent content in Ultimate-Member on Aretiq AI</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 15 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://aretiq.ai/tags/ultimate-member/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-61967 — miniOrange OTP Verification Ultimate Member Password Reset Authentication Bypass</title><link>https://aretiq.ai/research/vul260815-cve-2026-61967-miniorange-otp-verification-ultimate-member-password-reset-authentication-bypass/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://aretiq.ai/research/vul260815-cve-2026-61967-miniorange-otp-verification-ultimate-member-password-reset-authentication-bypass/</guid><description>&lt;h1 id="cve-2026-61967--miniorange-otp-verification-ultimate-member-password-reset-authentication-bypass">CVE-2026-61967 — miniOrange OTP Verification Ultimate Member Password Reset Authentication Bypass&lt;/h1>
&lt;h2 id="1-overview">1. Overview&lt;/h2>
&lt;p>A vulnerability exists in the miniOrange OTP Verification plugin for WordPress (versions 5.5.1 and earlier) that allows an unauthenticated attacker to bypass OTP verification during the Ultimate Member password reset flow. The plugin&amp;rsquo;s &lt;code>um_reset_password_process_hook&lt;/code> handler processes password reset requests without checking whether the required OTP was actually validated, relying solely on a publicly available WordPress nonce for authorization. An attacker can submit the password reset form for any user account, including administrators, and receive a valid password reset URL in the HTTP response, enabling full account takeover without any OTP or credential. The vendor addressed this vulnerability in version 5.5.2 by adding OTP session validation and username integrity checks.&lt;/p></description></item></channel></rss>