
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-9967 is a privilege escalation via account takeover vulnerability in the Orion SMS OTP Verification plugin for WordPress. It affects all versions up to and including 1.1.7, and was disclosed on October 15, 2025, by Wordfence. The flaw allows unauthenticated attackers to change any user's password to a one-time password if the attacker knows the target user's phone number. It carries a CVSS v3.1 base score of 9.8 (Critical), assigned by Wordfence (Wordfence, Red Hat CVE).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel): the plugin's password reset flow does not properly validate a user's identity before allowing a password update. The vulnerable logic is exposed in the plugin's client-side reset password JavaScript (reset-password.js), which interacts with a backend endpoint that lacks adequate server-side identity verification. An unauthenticated attacker can trigger a password reset for any account by supplying only the target user's phone number, bypassing standard authentication controls entirely (Wordfence, WordPress Plugin Trac).
Successful exploitation allows a remote, unauthenticated attacker to take over any WordPress user account — including administrator accounts — by resetting their password to an attacker-controlled OTP. This results in full compromise of confidentiality, integrity, and availability of the affected WordPress site, as an attacker with admin access can install malicious plugins, exfiltrate data, deface the site, or pivot to the underlying server infrastructure (Wordfence, Red Hat CVE).
/wp-content/plugins/orion-sms-otp-verification/./wp-content/plugins/orion-sms-otp-verification/; unexpected new admin user accounts or changes to existing user roles in the WordPress database.The primary remediation is to update the Orion SMS OTP Verification plugin to a version beyond 1.1.7 as soon as a patched release is available. If no patched version is available, site administrators should immediately disable or remove the plugin to eliminate the attack surface. Additionally, administrators should audit all WordPress user accounts for unauthorized password changes, review authentication logs for suspicious activity, and consider implementing additional authentication controls such as two-factor authentication on the WordPress admin panel (Wordfence, Feedly).
Wordfence disclosed and assigned the CVE, publishing it in their weekly WordPress vulnerability report for October 13–19, 2025 (Wordfence Blog). The vulnerability was noted by several security aggregators and community accounts on Bluesky and Mastodon/infosec.exchange shortly after disclosure, though no major media coverage or significant researcher commentary beyond standard aggregation has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."