top of page
perceptive_background_267k.jpg

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to …

Published:

28 mei 2026 om 22:00:00

Alert date:

29 mei 2026 om 09:01:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

The OTP Login With Phone Number plugin for WordPress contains an authentication bypass vulnerability in versions 1.8.50 through 1.8.60. The flaw exists in the Firebase verification flow where the lwp_ajax_register AJAX handler fails to properly bind Firebase sessions to phone numbers. The idehweb_lwp_activate_through_firebase() function validates Firebase OTP sessions but never compares the returned phoneNumber against the victim's stored phone number. This allows unauthenticated attackers to authenticate as any user with a stored phone number, including administrators, by verifying their own Firebase session while supplying the victim's phone number in the request.

Technical details

Mitigation steps:

Affected products:

WordPress OTP Login With Phone Number Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page