Impact
The OTP Login & Register WooCommerce plugin implements an OTP mechanism that is intended to provide two‑factor authentication for WordPress sites. In versions up to and including 2.7.2 an authentication bypass exists because the rate‑limit counter is keyed only to an attacker‑controlled cookie field, whereas the OTP value is generated with PHP’s non‑cryptographic rand() over a 9,000‑value space. The plugin also exposes OTP issuance and verification endpoints as unauthenticated AJAX actions without nonce or capability checks. As a result, any user with knowledge of a target account’s registered phone number can repeatedly request a new OTP, reset the counter by changing the cookie, brute‑force the OTP, and obtain a valid authentication cookie for the target account, including administrator accounts, via wp_set_auth_cookie() and login_user_with_otp(). This flaw is a classic example of authentication bypass (CWE‑434).
Affected Systems
Any WordPress site that installs the xootix:OTP Login & Register WooCommerce plugin in a version 2.7.2 or lower is vulnerable. The plugin is tied to WooCommerce and WordPress, but the vulnerability does not affect core WordPress or WooCommerce directly. The flaw manifests publicly via the website’s front‑end and AJAX interfaces, allowing remote attackers to exploit it from any location with network access to the site.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk, suggesting that while the impact is significant, it is not at the highest level of concern. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, implying no documented public exploits yet. The attack vector is likely remote over HTTP, and the only prerequisite is knowledge of a target account’s registered phone number, which can sometimes be discovered from publicly visible user profiles or via social engineering. Because the OTP counter can be reset by rotating the cookie, an attacker can perform thousands of attempts without triggering server‑side rate limiting, making the bypass feasible even against highly active sites.
OpenCVE Enrichment