top of page
perceptive_background_267k.jpg

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for C…

Published:

26 mei 2026 om 22:00:00

Alert date:

27 mei 2026 om 15:06:57

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

The Login with OTP plugin for WordPress versions up to 1.6 contains an authentication bypass vulnerability. This is due to an incomplete fix for CVE-2024-11178 where rate-limiting checks are only applied to OTP generation, not validation. The 6-digit OTP has no expiration, allowing attackers to brute-force the 900,000-value OTP space. Successful exploitation grants attackers valid authentication cookies for any user account, including administrators, leading to full site compromise.

Technical details

Mitigation steps:

Affected products:

WordPress Login with OTP plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page