Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfjg-jw2h-6xcq

Опубликовано: 05 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.

EPSS

Процентиль: 22%
0.00296
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 месяцев назад

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.

EPSS

Процентиль: 22%
0.00296
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287