Impact
The Registration & Login with Mobile Phone Number for WooCommerce plugin is vulnerable to authentication bypass because it does not properly verify a user’s identity before calling the fma_lwp_set_session_php_fun() function. As a result, an unauthenticated attacker can log in as any site user, including administrators, without needing a valid password, fully compromising account control.
Affected Systems
Any WordPress site running the FmeAddons Registration & Login with Mobile Phone Number for WooCommerce plugin of version 1.3.1 or earlier is affected. The vulnerability applies to all plugin instances that rely on this authentication flow, regardless of site size or configuration.
Risk and Exploitability
The CVSS score of 9.8 demonstrates a critical risk to confidentiality, integrity, and availability. The EPSS score of less than 1% indicates that exploit attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the authentication bypass could be triggered remotely through normal site interactions, allowing an attacker who can reach the site to authenticate without credentials and gain full administrative privileges.
OpenCVE Enrichment