Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-33cg-9r8g-hqm4

Опубликовано: 16 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.

EPSS

Процентиль: 22%
0.00299
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
27 дней назад

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.

EPSS

Процентиль: 22%
0.00299
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287