Description
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper restriction of authentication attempts vulnerability that allows attackers to bypass two-factor authentication by guessing TOTP codes without limits. Attackers who know an account password can submit unlimited 6-digit verification codes to VerificationCodeFormProcess.php to take over member, affiliate, or administrator accounts.
Published: 2026-10-08
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Bypass of two-factor authentication that enables account takeover
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in pH7 Builder allows an attacker who has obtained a user’s password to circumvent the second authentication factor by submitting an unlimited number of 6‑digit one‑time passwords to the VerificationCodeFormProcess.php endpoint, leading directly to account takeover. This flaw is a manifestation of CWE‑307.

Affected Systems

The flaw affects all installations of pH7 Social Dating CMS (pH7Builder) from ph7software running any version earlier than 18.5.0. No sub‑module or more granular version data is documented.

Risk and Exploitability

The CVSS score of 7.6 classifies this issue as high severity. The EPSS score is not available, so the precise exploitation likelihood is unknown, yet the vulnerability can be exploited remotely via the web interface. It is not listed in the CISA KEV catalog. Because attackers who know the account password can brute‑force the 6‑digit TOTP without limit, the risk to privileged accounts is significant. The lack of a lockout or rate‑limit mechanism makes successful exploitation straightforward.

Generated by OpenCVE AI on October 8, 2026 at 15:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pH7Builder to version 18.5.0 or later where the verification attempt restriction has been implemented.
  • If an upgrade cannot be performed immediately, temporarily disable two‑factor authentication for affected accounts until a patch can be applied.
  • Add rate‑limiting or CAPTCHA protection to the VerificationCodeFormProcess.php endpoint to prevent unlimited code submissions.
  • Monitor authentication logs for repeated 2FA failures and lock accounts that exceed reasonable attempt thresholds.

Generated by OpenCVE AI on October 8, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Ph7software
Ph7software ph7builder
Vendors & Products Ph7software
Ph7software ph7builder

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper restriction of authentication attempts vulnerability that allows attackers to bypass two-factor authentication by guessing TOTP codes without limits. Attackers who know an account password can submit unlimited 6-digit verification codes to VerificationCodeFormProcess.php to take over member, affiliate, or administrator accounts.
Title pH7Builder before 18.5.0 2FA Brute Force via VerificationCodeFormProcess.php
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ph7software Ph7builder
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T18:01:47.983Z

Reserved: 2026-10-08T14:06:00.383Z

Link: CVE-2026-107638

cve-icon Vulnrichment

Updated: 2026-10-08T18:01:43.671Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T15:17:46.930

Modified: 2026-10-08T18:17:25.320

Link: CVE-2026-107638

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:04Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts