top of page
perceptive_background_267k.jpg

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for C…

Published:

26 May 2026 at 22:00:00

Alert date:

27 May 2026 at 15:06:57

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

The Login with OTP plugin for WordPress versions up to 1.6 contains an authentication bypass vulnerability. This is due to an incomplete fix for CVE-2024-11178 where rate-limiting checks are only applied to OTP generation, not validation. The 6-digit OTP has no expiration, allowing attackers to brute-force the 900,000-value OTP space. Successful exploitation grants attackers valid authentication cookies for any user account, including administrators, leading to full site compromise.

Technical details

Mitigation steps:

Affected products:

WordPress Login with OTP plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page