What the vulnerability does
01Description
The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to obtain login codes for administrators. This does require an attacker have access to the phone number configured for an account, which can be obtained via social engineering or reconnaissance.
Explanation of Vulnerability in Simple Terms
02Summary
The OTP Login & Register WooCommerce plugin versions 2.2 and earlier contain an authentication bypass vulnerability. Attackers can bypass the one-time password (OTP) verification mechanism without needing valid credentials or user interaction. This allows unauthorized access to user accounts and administrative functions. Update to a version newer than 2.2 immediately.
What an attacker can do
03Attacker Capabilities
Bypass OTP verification and gain unauthorized access to user accounts without valid credentials.
Potential impact on your site
04Site Impact
User accounts and admin functions can be compromised without valid login credentials or OTP codes.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
May 17, 2023
CVE published
April 8, 2026
Record updated