Impact
The Happy Coders OTP Login for WooCommerce plugin before version 2.8 fails to confirm that an OTP was validated before authenticating a user identifier. This allows attackers without prior authentication to log in as any existing user, including administrators, and to create new accounts, effectively taking over accounts. The vulnerability arises from a missing verification step in the auto‑login routine, which omits the critical check that the supplied OTP matches the expected code. An attacker can exploit this flaw by simply calling the auto‑login endpoint with a username and an arbitrary OTP, gaining immediate access to the target account.
Affected Systems
WordPress sites running the Happy Coders OTP Login for WooCommerce plugin with a version earlier than 2.8 are impacted. Any environment that hosts the plugin – regardless of the site’s user base or configuration – is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of less than 1% suggests a low probability of public exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw permits unauthenticated users to take over accounts, the risk to confidentiality and integrity is high. The likely attack vector is a remote, internet‑based exploitation of the auto‑login endpoint, requiring no prior authentication.
OpenCVE Enrichment