Impact
The vulnerability allows an unauthenticated attacker to request a one-time password (OTP) for any user account via the OTP Login With Phone Number, OTP Verification plugin. Because the plugin does not enforce any rate limiting or invalidate the OTP after a failed guess, a brute‑force attack on the short numeric code can succeed within a reasonable number of attempts, permitting the attacker to authenticate as the target, including administrators. This represents an authentication bypass that can compromise confidentiality, integrity, and availability of the site and its users.
Affected Systems
WordPress sites that have the OTP Login With Phone Number, OTP Verification plugin installed prior to version 1.8.71. All user accounts exposed through this plugin are vulnerable, regardless of role. The issue affects any WordPress instance that has not applied the security patch included in 1.8.71 or later.
Risk and Exploitability
The attack can be performed from any location with internet connectivity to the targeted WordPress site, making it a remote unauthenticated vector. Since the OWASP Common Weakness enumeration points to missing rate limiting, an attacker can iterate guesses quickly without detection. Exploitability is high because no special privileges or additional configuration are required. No official KEV listing or EPSS data is available, but the lack of protective controls makes this a critical asset risk.
OpenCVE Enrichment