top of page
perceptive_background_267k.jpg

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to …

Published:

28 May 2026 at 22:00:00

Alert date:

29 May 2026 at 14:01:48

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

The OTP Login With Phone Number plugin for WordPress contains an authentication bypass vulnerability in versions 1.8.50 through 1.8.60. The vulnerability exists in the Firebase verification flow where the AJAX handler fails to bind Firebase sessions to the supplied phone number. The idehweb_lwp_activate_through_firebase() function validates Firebase OTP sessions but never compares the Firebase-returned phone number against the victim's stored phone number. This allows unauthenticated attackers to authenticate as any user with a stored phone number by verifying their own Firebase session while supplying the victim's phone number in the request. The vulnerability affects all user accounts including administrators, making it particularly critical for WordPress sites using this plugin.

Technical details

Mitigation steps:

Affected products:

WordPress OTP Login With Phone Number plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page