WooCommerce Registration & Login with Mobile Phone Number Plugin Authentication Bypass Vulnerability
Vulnerability
An authentication bypass vulnerability has been identified in the Registration & Login with Mobile Phone Number for WooCommerce plugin, affecting all versions through 1.3.1. The vulnerability arises because the plugin fails to properly verify user identity before authenticating users via the fma_lwp_set_session_php_fun() function. This flaw allows unauthenticated attackers to authenticate as any user, including administrators, without needing a valid password.
Impact
Exploitation of this vulnerability allows for authentication bypass, enabling attackers to gain unauthorized access to user accounts, including those of administrators.
Remediation
Users can update to version 1.3.2 or a newer patched version to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
