External risk intelligence

Orion SMS OTP WordPress Plugin Account Takeover Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-9967

This is a WordPress plugin designed for SMS OTP verification. Such plugins are commonly deployed on public-facing websites to handle user authentication, login processes, or password resets, making the vulnerable functionality directly accessible to internet users.

Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in a WordPress plugin used for SMS One-Time Password (OTP) verification. The flaw allows unauthenticated attackers, knowing a user's phone number, to potentially take over accounts by changing passwords without proper identity validation. This could impact user access and data integrity if systems using this plugin are exposed to the internet.

  • Unauthenticated attackers can take over accounts.
  • Critical vulnerability in WordPress SMS OTP plugin.
  • Confirm relevance and assess exposure risk.

Attack Path

How an attacker could exploit the issue

An attacker could target users of the Orion SMS OTP Verification plugin for WordPress by leveraging its flawed identity validation during password resets. Without needing any prior authentication or access, an attacker could exploit this vulnerability if they know a target user's phone number. This could allow the attacker to take over user accounts by changing their passwords.

  • Unauthenticated access to a site with the plugin.
  • Triggering password reset without proper validation.
  • Account takeover via arbitrary password changes.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could gain unauthorized access to WordPress sites and perform account takeovers if they know a user's phone number. This could lead to the compromise of user accounts and potentially sensitive information associated with those accounts.

  • User accounts and associated data.
  • By exploiting identity validation flaws.
  • Unauthorized account access and control.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Orion SMS OTP Verification plugin's privilege escalation vulnerability requires coordination between application owners responsible for WordPress sites, infrastructure teams managing hosting environments, and potentially vendor management if the plugin was acquired through a third party. The immediate first step is to identify all WordPress instances using this plugin, confirm their internet accessibility and business criticality, and then assign ownership for remediation planning.

  • WordPress application owners.
  • Confirm plugin reachability and criticality.
  • Plan targeted remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Orion SMS OTP Verification plugin?

This WordPress plugin adds a layer of security to site logins and password resets by sending a One-Time Password (OTP) via text message. It is designed to verify user identity by confirming access to a registered mobile phone number, ensuring that only the legitimate account owner can complete authentication processes.

What does CWE-288 mean for CVE-2025-9967?

CWE-288 refers to authentication bypass using an alternate path or channel. In the context of this CVE, it means the plugin fails to properly verify a user's identity before allowing a password update. Instead of requiring a valid session or the correct secret code, the plugin accepts a request to change the account password based on insufficient proof of identity.

How can an attacker trigger this vulnerability?

An attacker can initiate an account takeover by sending a specially crafted request to the plugin that triggers a password reset. The flaw is triggered solely by knowing the target user's phone number. Importantly, the attacker does not need to be logged into the site or possess a previous valid session to misuse this feature.

Is my WordPress site at risk according to Halo Surface Signal?

Halo Surface Signal identifies this plugin as likely to be internet-facing, as its core function is to handle public-facing authentication and password reset workflows. If your site is accessible over the internet, the vulnerable plugin functions are exposed to external users, increasing the likelihood that an attacker could reach and exploit this flaw.

What are the first steps to address this CVE?

Begin by auditing your WordPress environment to identify if and where the Orion SMS OTP Verification plugin is currently active. Once identified, evaluate the criticality of the site and the plugin's role in your authentication workflow. Establish ownership for the site to monitor for updates or determine if the plugin should be temporarily disabled to prevent unauthorized account access.

References