# OTP Login With Phone Number, OTP Verification <= 1.8.74 - Unauthenticated Authentication Bypass via OTP Brute Force

- **ID:** WPSEC-2026-0723
- **Plugin:** OTP Login With Phone Number, OTP Verification (`login-with-phone-number`), https://wordpress.org/plugins/login-with-phone-number/
- **Affected versions:** from 1.8.71 before 1.8.76
- **Fixed in:** 1.8.76 (Update to 1.8.76 or later.)
- **Severity:** High 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-307
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/login-with-phone-number
- **Fix released:** 2026-10-09
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0723/

## Description

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass via OTP brute force in versions 1.8.71 up to, and including, 1.8.74. The wrong-attempt lockout added in 1.8.71 is ineffective. lwp_generate_token() resets the attempt counter every time a code is issued, and code requests have no rate limit. The lwp_ajax_register handler also counts failed attempts with a non-atomic read-then-write of user meta, so parallel requests can get past the limit. This makes it possible for unauthenticated attackers to make an unlimited number of guesses at a user's one-time login code, log in as that user (including administrators) and take over the account. As a side effect, the victim can be flooded with OTP messages.

## References

- https://wpsec.com/vuln/WPSEC-2026-0723/
- https://plugins.svn.wordpress.org/login-with-phone-number/tags/1.8.76/
- https://wordpress.org/plugins/login-with-phone-number/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0723/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
