OTP Login With Phone Number, OTP Verification <= 1.8.74 - Unauthenticated Authentication Bypass via OTP Brute Force
- ID
- WPSEC-2026-0723
- Plugin
- OTP Login With Phone Number, OTP Verification (login-with-phone-number)
- Affected
- from 1.8.71 before 1.8.76
- Remediation
- Update to 1.8.76 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-307
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- OTP Login With Phone Number, OTP Verification on WPSec AttackSurface
- Fix released
- Published
Description
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass via OTP brute force in versions 1.8.71 up to, and including, 1.8.74. The wrong-attempt lockout added in 1.8.71 is ineffective. lwp_generate_token() resets the attempt counter every time a code is issued, and code requests have no rate limit. The lwp_ajax_register handler also counts failed attempts with a non-atomic read-then-write of user meta, so parallel requests can get past the limit. This makes it possible for unauthenticated attackers to make an unlimited number of guesses at a user's one-time login code, log in as that user (including administrators) and take over the account. As a side effect, the victim can be flooded with OTP messages.
References
- https://wpsec.com/vuln/WPSEC-2026-0723/
- https://plugins.svn.wordpress.org/login-with-phone-number/tags/1.8.76/
- https://wordpress.org/plugins/login-with-phone-number/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS