Happy Coders OTP Login for WooCommerce Authentication Bypass Vulnerability Allowing Account Takeover

Vulnerability

An authentication bypass vulnerability has been identified in the Happy Coders OTP Login for WooCommerce WordPress plugin, affecting versions prior to 2.8. The vulnerability arises because the plugin does not properly verify whether a one-time password (OTP) has been validated before allowing user authentication based on a provided identifier. This flaw enables unauthenticated attackers to log in as any existing user, including those with administrative privileges, and to create new user accounts.

Impact

Exploitation of this vulnerability allows for unauthorized login as any existing user, including administrators, and the creation of new user accounts.

Remediation

Users are advised to update the Happy Coders OTP Login for WooCommerce WordPress plugin to version 2.8 or later.

Added: Jul 16, 2026, 7:27 AM
Updated: Jul 16, 2026, 7:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
9.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.