Impact
The vulnerability allows an unauthenticated attacker to request a one‑time password (OTP) for any user account via the OTP Login With Phone Number, OTP Verification plugin. Because the plugin does not enforce any rate limiting or invalidate the OTP after a failed guess, a brute‑force attack on the short numeric code can succeed within a reasonable number of attempts, permitting the attacker to authenticate as the target, including administrators. This represents an authentication bypass that can compromise confidentiality integrity, and availability of the site and its users.
Affected Systems
WordPress sites that have the OTP Login With Phone Number, OTP Verification plugin installed prior to version 1.8.71. All user accounts exposed through this plugin are vulnerable, regardless of role. The issue affects any WordPress instance that has not applied the security patch included in 1.8.71 or later.
Risk and Exploitability
The attack can be performed from any location with internet connectivity to the targeted WordPress site, making it a remote unauthenticated vector. Since the OWASP Common Weakness enumeration points to missing rate limiting, an attacker can iterate guesses quickly without detection. Exploitability is high because no special privileges or additional configuration are required. The CVSS score is 9.1, the EPSS score is <1 %, and the vulnerability is not listed in the CISA KEV catalog. This makes the risk high because exploitability is easy and no protective controls exist. Based on the description, it is inferred that the attack is conducted remotely and unauthenticated via the plugin’s public OTP request endpoint.
OpenCVE Enrichment