Description
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.
Published: 2026-07-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Happy Coders OTP Login for WooCommerce plugin before version 2.8 fails to confirm that an OTP was validated before authenticating a user identifier. This allows attackers without prior authentication to log in as any existing user, including administrators, and to create new accounts, effectively taking over accounts. The vulnerability arises from a missing verification step in the auto‑login routine, which omits the critical check that the supplied OTP matches the expected code. An attacker can exploit this flaw by simply calling the auto‑login endpoint with a username and an arbitrary OTP, gaining immediate access to the target account.

Affected Systems

WordPress sites running the Happy Coders OTP Login for WooCommerce plugin with a version earlier than 2.8 are impacted. Any environment that hosts the plugin – regardless of the site’s user base or configuration – is potentially vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. The EPSS score of less than 1% suggests a low probability of public exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw permits unauthenticated users to take over accounts, the risk to confidentiality and integrity is high. The likely attack vector is a remote, internet‑based exploitation of the auto‑login endpoint, requiring no prior authentication.

Generated by OpenCVE AI on July 31, 2026 at 02:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Happy Coders OTP Login for WooCommerce plugin to version 2.8 or newer.
  • If the plugin is not required, uninstall or disable it on the WordPress installation.
  • Immediately review audit logs for unauthorized login attempts and reset passwords for accounts that may have been compromised.
  • If an immediate upgrade is not possible, restrict access to the auto‑login endpoint (hcotp_auto_login_user) behind authentication or firewall rules.

Generated by OpenCVE AI on July 31, 2026 at 02:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.
Title Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-16T15:33:35.211Z

Reserved: 2026-06-17T08:25:07.733Z

Link: CVE-2026-12492

cve-icon Vulnrichment

Updated: 2026-07-16T15:26:44.365Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:30:05Z

Weaknesses