WooCommerce Registration & Login with Mobile Phone Number Plugin Authentication Bypass Vulnerability

Vulnerability

An authentication bypass vulnerability has been identified in the Registration & Login with Mobile Phone Number for WooCommerce plugin, affecting all versions through 1.3.1. The vulnerability arises because the plugin fails to properly verify user identity before authenticating users via the fma_lwp_set_session_php_fun() function. This flaw allows unauthenticated attackers to authenticate as any user, including administrators, without needing a valid password.

Impact

Exploitation of this vulnerability allows for authentication bypass, enabling attackers to gain unauthorized access to user accounts, including those of administrators.

Remediation

Users can update to version 1.3.2 or a newer patched version to address this vulnerability.

Added: Jan 17, 2026, 9:21 AM
Updated: Jan 17, 2026, 9:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
2.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.