Executive brief
The Login with OTP plugin for WordPress, which provides one-time password functionality for user logins, contains a security flaw that allows attackers to bypass authentication. By exploiting a lack of rate-limiting and expiration on login codes, an attacker can gain full access to any user account, including administrators. This could lead to a complete takeover of the website and theft of sensitive data.
Technical details
The vulnerability is an authentication bypass resulting from an incomplete fix for a previous security issue (CVE-2024-11178). While a rate-limit check was added to the 'otpl_login_action()' function, it was only implemented in the OTP-generation logic and not the validation logic. Furthermore, the 6-digit numeric OTPs do not expire. This allows a remote, unauthenticated attacker to perform a brute-force attack against the 900,000 possible OTP values for any user. A successful attack results in a valid authentication session via 'wp_set_auth_cookie()', granting the attacker full administrative control over the WordPress site.
Affected products
- WordPress Login with OTP Up to, and including, 1.6
Timeline
- 2026-05-27: advisory: NVD published the vulnerability details.
References
- https://plugins.trac.wordpress.org/browser/otp-login/tags/1.6/lib/otpl-class.php
- https://plugins.trac.wordpress.org/browser/otp-login/tags/1.6/lib/otpl-class.php
- https://plugins.trac.wordpress.org/browser/otp-login/tags/1.6/lib/otpl-class.php
- https://plugins.trac.wordpress.org/browser/otp-login/tags/1.6/lib/otpl-class.php
- https://plugins.trac.wordpress.org/browser/otp-login/trunk/lib/otpl-class.php
- https://plugins.trac.wordpress.org/browser/otp-login/trunk/lib/otpl-class.php