What is CVE-2026-61957?
CVE-2026-61957 is an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability affecting the miniorange OTP Verification plugin for WordPress in versions <= 5.5.1. This flaw allows remote attackers to inject malicious scripts into a website due to improper input sanitization. It is recommended to update to the latest version of the plugin.
Azərbaycanca: CVE-2026-61957, miniorange OTP Doğrulama plaginin 5.5.1 və daha əvvəlki versiyalarında autentifikasiya tələb etməyən Saxlanılmış XSS (Cross-Site Scripting) zəifliyidir. Bu boşluq uzaqdan hücum edənə istifadəçi girişlərini təmizləməyərək vebsayta zərərli skript yerləşdirməyə imkan verir. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the miniorange OTP Verification plugin are affected by CVE-2026-61957?
This vulnerability affects versions 5.5.1 and earlier of the plugin.
What action is recommended to protect against CVE-2026-61957?
It is recommended to update to the latest version of the plugin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.