---
id: CVE-2025-9967
title: >-
  The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege
  escalation via account takeover in all versions up to, and including, 1.1.7
summary: >-
  The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege
  escalation via account takeover in all versions up to, and including, 1.1.7.
  This is due to the plugin not properly validating a user's identity prior to
  upda…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-288
published: '2025-10-15'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9967'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/orion-sms-otp-verification/trunk/vendor/js/reset-password.js
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/log/orion-sms-otp-verification/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/b121fdb4-93a8-400c-89c2-3195cb40e03c?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.00428
epssPercentile: 0.34387
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/jFriedli/CVE-2025-9967'
  checkedAt: '2026-09-26T00:23:14.510Z'
exploitAvailable: true
ingestedAt: '2026-09-26T00:22:39.961Z'
---

## Overview

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's password to a one-time password if the attacker knows the user's phone number

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
