Happy Coders OTP Login
- < 2.8
An authentication bypass vulnerability has been identified in the Happy Coders OTP Login for WooCommerce WordPress plugin, affecting versions prior to 2.8. The vulnerability arises because the plugin does not properly verify whether a one-time password (OTP) has been validated before allowing user authentication based on a provided identifier. This flaw enables unauthenticated attackers to log in as any existing user, including those with administrative privileges, and to create new user accounts.
Exploitation of this vulnerability allows for unauthorized login as any existing user, including administrators, and the creation of new user accounts.
Users are advised to update the Happy Coders OTP Login for WooCommerce WordPress plugin to version 2.8 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.