OTP Login With Phone Number, OTP Verification <= 1.8.74 - Unauthenticated Authentication Bypass via OTP Brute Force

High 8.1 CWE-307Fixed in 1.8.76
ID
WPSEC-2026-0723
Plugin
OTP Login With Phone Number, OTP Verification (login-with-phone-number)
Affected
from 1.8.71 before 1.8.76
Remediation
Update to 1.8.76 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-307
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
OTP Login With Phone Number, OTP Verification on WPSec AttackSurface
Fix released
Published

Description

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass via OTP brute force in versions 1.8.71 up to, and including, 1.8.74. The wrong-attempt lockout added in 1.8.71 is ineffective. lwp_generate_token() resets the attempt counter every time a code is issued, and code requests have no rate limit. The lwp_ajax_register handler also counts failed attempts with a non-atomic read-then-write of user meta, so parallel requests can get past the limit. This makes it possible for unauthenticated attackers to make an unlimited number of guesses at a user's one-time login code, log in as that user (including administrators) and take over the account. As a side effect, the victim can be flooded with OTP messages.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0