Executive brief
A security flaw in the Happy Coders OTP Login plugin for WooCommerce allows unauthorized individuals to bypass the login process. By exploiting this issue, an attacker can gain full access to any existing user account, including administrator accounts, or create new accounts without a valid password. This could lead to a total takeover of the online store, theft of customer data, and disruption of business operations.
Technical details
The Happy Coders OTP Login for WooCommerce plugin before version 2.8 contains an authentication bypass vulnerability in the hcotp_auto_login_user function. The root cause is a failure to verify that a one-time password (OTP) was actually validated before authenticating a user based on a supplied identifier. An unauthenticated remote attacker can exploit this by providing a target user's identifier to bypass authentication entirely. This allows for full account takeover of any user, including administrators, and the ability to register new accounts. The issue is fixed in version 2.8.
Affected products
- Happy Coders Happy Coders OTP Login for WooCommerce < 2.8
Timeline
- 2026-06-25: disclosed: Vulnerability publicly disclosed by WPScan
- 2026-07-16: advisory: CVE published to NVD dataset