Impact
The vulnerability is a missing authorization flaw that allows an attacker to exploit incorrectly configured access control levels within the WordPress plugin. The flaw can enable any remote user to access registration or login endpoints that should be protected, resulting in unauthorized account creation or authentication bypass. The weakness is identified as CWE‑862, indicating improper restriction of privileges.
Affected Systems
All installations of the FmeAddons Registration & Login with Mobile Phone Number for WooCommerce plugin from any version through 1.3.1 are affected. This includes any WordPress sites that have deployed the plugin and rely on its registration or login pages for user authentication.
Risk and Exploitability
The CVSS score of 9.8 classifies this as a high‑severity flaw, while the EPSS score of less than 1% suggests that exploitation is unlikely but possible under the right conditions. The vulnerability is not currently listed in the CISA KEV catalog. Attackers can reach the vulnerable functionality via publicly accessible URLs, so the primary attack vector is remote. Exploitation requires access to the WordPress site’s URLs and does not need elevated privileges, making it a significant risk for any site using the plugin.
OpenCVE Enrichment