WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in miniOrange OTP Login, Verification and SMS Notifications

OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification

4Reported vulnerabilities
9.8Highest CVSS score
5.5.4Latest version
5,000+Active installs

What to do now

Update miniOrange OTP Login, Verification and SMS Notifications to 5.5.2 or later. 4 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 4, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-14245 Critical 9.8 1.1% 0 to 5.5.1 (inclusive) 5.5.2 July 9, 2026
CVE-2026-61967 Critical 9.8 0.3% 5.5.1 and earlier 5.5.2 August 11, 2026
CVE-2026-42731 Critical 9.8 0.3% 5.4.9 and earlier 5.5.0 May 24, 2026
CVE-2026-61957 High 7.2 0.1% 5.5.1 and earlier 5.5.2 July 27, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.