top of page
perceptive_background_267k.jpg

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time…

Published:

5 August 2026 at 00:00:00

Alert date:

5 August 2026 at 19:04:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

The OTP Login With Phone Number, OTP Verification WordPress plugin versions before 1.8.71 contains a critical security flaw. The plugin fails to limit the number of OTP verification attempts and does not invalidate a one-time login code after an incorrect guess. Any unauthenticated user can request a login code for any account on the system. Since the OTP is a short numeric code, attackers can brute-force it with relative ease. Successful exploitation allows complete account takeover, including administrator accounts. This vulnerability poses a severe risk to WordPress sites using this plugin. No authentication is required to exploit this vulnerability, making it highly accessible to attackers.

Technical details

Mitigation steps:

Affected products:

OTP Login With Phone Number OTP Verification WordPress plugin (before 1.8.71)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page