CVE-2023-2706 HIGH

CVE-2023-2706: OTP Login Woocommerce & Gravity Forms <= 2.2 - Authentication Bypass to Privilege Escalation

Vendor Xootix
Product OTP Login & Register Woocommerce
Weakness CWE-287 · Improper authentication
Published May 17, 2023
Last update April 8, 2026

CVSS base score

8.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to obtain login codes for administrators. This does require an attacker have access to the phone number configured for an account, which can be obtained via social engineering or reconnaissance.

Explanation of Vulnerability in Simple Terms

02Summary

The OTP Login & Register WooCommerce plugin versions 2.2 and earlier contain an authentication bypass vulnerability. Attackers can bypass the one-time password (OTP) verification mechanism without needing valid credentials or user interaction. This allows unauthorized access to user accounts and administrative functions. Update to a version newer than 2.2 immediately.

What an attacker can do

03Attacker Capabilities

Bypass OTP verification and gain unauthorized access to user accounts without valid credentials.

Potential impact on your site

04Site Impact

User accounts and admin functions can be compromised without valid login credentials or OTP codes.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

May 17, 2023 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE