Description
The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the attacker-controlled `xoo_ml_user_ip_data` cookie's `ip_address` field, allowing unlimited counter resets by simply rotating the cookie, while the OTP itself is generated with PHP's non-cryptographic `rand()` function over a default space of only 9,000 possible values (1000–9999), and both the OTP issuance endpoint (`xoo_ml_login_with_otp`) and verification endpoint (`xoo_ml_otp_form_submit`) are registered as unauthenticated `wp_ajax_nopriv` actions with no nonce or capability checks. This makes it possible for unauthenticated attackers to brute-force the OTP for any registered account and obtain a full WordPress authentication session — including for administrator accounts — via `wp_set_auth_cookie()` in `login_user_with_otp()`. Exploitation requires the attacker to know the target user's registered phone number, which is used to trigger OTP issuance via the unauthenticated `xoo_ml_login_with_otp` endpoint.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Patch
AI Analysis

Impact

The OTP Login & Register WooCommerce plugin implements an OTP mechanism that is intended to provide two‑factor authentication for WordPress sites. In versions up to and including 2.7.2 an authentication bypass exists because the rate‑limit counter is keyed only to an attacker‑controlled cookie field, whereas the OTP value is generated with PHP’s non‑cryptographic rand() over a 9,000‑value space. The plugin also exposes OTP issuance and verification endpoints as unauthenticated AJAX actions without nonce or capability checks. As a result, any user with knowledge of a target account’s registered phone number can repeatedly request a new OTP, reset the counter by changing the cookie, brute‑force the OTP, and obtain a valid authentication cookie for the target account, including administrator accounts, via wp_set_auth_cookie() and login_user_with_otp(). This flaw is a classic example of authentication bypass (CWE‑434).

Affected Systems

Any WordPress site that installs the xootix:OTP Login & Register WooCommerce plugin in a version 2.7.2 or lower is vulnerable. The plugin is tied to WooCommerce and WordPress, but the vulnerability does not affect core WordPress or WooCommerce directly. The flaw manifests publicly via the website’s front‑end and AJAX interfaces, allowing remote attackers to exploit it from any location with network access to the site.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity risk, suggesting that while the impact is significant, it is not at the highest level of concern. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, implying no documented public exploits yet. The attack vector is likely remote over HTTP, and the only prerequisite is knowledge of a target account’s registered phone number, which can sometimes be discovered from publicly visible user profiles or via social engineering. Because the OTP counter can be reset by rotating the cookie, an attacker can perform thousands of attempts without triggering server‑side rate limiting, making the bypass feasible even against highly active sites.

Generated by OpenCVE AI on September 11, 2026 at 06:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the OTP Login & Register WooCommerce plugin to any released version newer than 2.7.2.
  • If an upgrade cannot be performed immediately, block the unauthenticated AJAX actions xoo_ml_login_with_otp and xoo_ml_otp_form_submit with a firewall or security plugin so that only authenticated users can access them.
  • After patching or blocking the endpoints, audit existing user sessions and logs for any unauthorized access and consider implementing a more secure OTP generation mechanism (e.g., random_int()) for future implementations.

Generated by OpenCVE AI on September 11, 2026 at 06:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Xootix
Xootix otp Login & Register Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Xootix
Xootix otp Login & Register Woocommerce

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the attacker-controlled `xoo_ml_user_ip_data` cookie's `ip_address` field, allowing unlimited counter resets by simply rotating the cookie, while the OTP itself is generated with PHP's non-cryptographic `rand()` function over a default space of only 9,000 possible values (1000–9999), and both the OTP issuance endpoint (`xoo_ml_login_with_otp`) and verification endpoint (`xoo_ml_otp_form_submit`) are registered as unauthenticated `wp_ajax_nopriv` actions with no nonce or capability checks. This makes it possible for unauthenticated attackers to brute-force the OTP for any registered account and obtain a full WordPress authentication session — including for administrator accounts — via `wp_set_auth_cookie()` in `login_user_with_otp()`. Exploitation requires the attacker to know the target user's registered phone number, which is used to trigger OTP issuance via the unauthenticated `xoo_ml_login_with_otp` endpoint.
Title OTP Login & Register Woocommerce <= 2.7.2 - Unauthenticated Authentication Bypass via Brute Force
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Xootix Otp Login & Register Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T13:46:23.712Z

Reserved: 2026-06-14T13:32:13.820Z

Link: CVE-2026-12215

cve-icon Vulnrichment

Updated: 2026-09-11T13:39:00.543Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:20.013

Modified: 2026-09-11T14:17:25.320

Link: CVE-2026-12215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:57:10Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type