CVE-2025-14948: CYBERLORD92 Miniorange OTP Verification And Sms Notification For Woocommerce

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `enable_wc_sms_notification` AJAX action in all versions up to, and including, 4.3.8. This makes it possible for unauthenticated attackers to enable or disable SMS notification settings for WooCommerce orders.

Affected products

  • CYBERLORD92 Miniorange OTP Verification And Sms Notification For Woocommerce: up to and including 4.3.8

Published 2026-01-10. Last modified 2026-06-17.