CVE-2025-9967
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-9967 is a privilege escalation via account takeover vulnerability in the Orion SMS OTP Verification plugin for WordPress. It affects all versions up to and including 1.1.7, and was disclosed on October 15, 2025, by Wordfence. The flaw allows unauthenticated attackers to change any user's password to a one-time password if the attacker knows the target user's phone number. It carries a CVSS v3.1 base score of 9.8 (Critical), assigned by Wordfence (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel): the plugin's password reset flow does not properly validate a user's identity before allowing a password update. The vulnerable logic is exposed in the plugin's client-side reset password JavaScript (reset-password.js), which interacts with a backend endpoint that lacks adequate server-side identity verification. An unauthenticated attacker can trigger a password reset for any account by supplying only the target user's phone number, bypassing standard authentication controls entirely (Wordfence, WordPress Plugin Trac).

Impact

Successful exploitation allows a remote, unauthenticated attacker to take over any WordPress user account — including administrator accounts — by resetting their password to an attacker-controlled OTP. This results in full compromise of confidentiality, integrity, and availability of the affected WordPress site, as an attacker with admin access can install malicious plugins, exfiltrate data, deface the site, or pivot to the underlying server infrastructure (Wordfence, Red Hat CVE).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.055%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Orion SMS OTP Verification plugin (versions ≤ 1.1.7) using tools like WPScan, Shodan, or by checking the plugin's presence via /wp-content/plugins/orion-sms-otp-verification/.
  2. Identify target user: Obtain the phone number associated with the target WordPress account (e.g., administrator) through OSINT, social engineering, or site-exposed user data.
  3. Trigger password reset: Send a crafted HTTP request to the plugin's password reset endpoint, supplying the target user's phone number without providing valid authentication credentials or a verified OTP.
  4. Set attacker-controlled password: Because the plugin does not validate the requester's identity, the backend accepts the request and updates the target user's password to the OTP value supplied or generated by the attacker.
  5. Account takeover: Log in to the WordPress site using the target user's credentials (phone number / new OTP password), gaining full access to the account and its privileges (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • Network: Unexpected or repeated HTTP POST requests to the Orion SMS OTP Verification plugin's password reset endpoint from unauthenticated or unknown IP addresses.
  • Logs: WordPress authentication logs showing successful logins from unfamiliar IP addresses or at unusual times for high-privilege accounts; password change events in WordPress audit logs not initiated by the account owner.
  • File System: New or modified plugin files in /wp-content/plugins/orion-sms-otp-verification/; unexpected new admin user accounts or changes to existing user roles in the WordPress database.
  • Process/Behavior: Unusual administrative actions (plugin installs, theme changes, new user creation) shortly after a password change event for an administrator account.

Mitigation and workarounds

The primary remediation is to update the Orion SMS OTP Verification plugin to a version beyond 1.1.7 as soon as a patched release is available. If no patched version is available, site administrators should immediately disable or remove the plugin to eliminate the attack surface. Additionally, administrators should audit all WordPress user accounts for unauthorized password changes, review authentication logs for suspicious activity, and consider implementing additional authentication controls such as two-factor authentication on the WordPress admin panel (Wordfence, Feedly).

Community reactions

Wordfence disclosed and assigned the CVE, publishing it in their weekly WordPress vulnerability report for October 13–19, 2025 (Wordfence Blog). The vulnerability was noted by several security aggregators and community accounts on Bluesky and Mastodon/infosec.exchange shortly after disclosure, though no major media coverage or significant researcher commentary beyond standard aggregation has been observed.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management