Junglewise Threat Intelligence

CVE-2026-8760: WordPress Login with OTP authentication bypass in otpl_login_action

CVE-2026-8760 · Severity: critical · CVSS 9.8 · Published 2026-05-27

Vendors: miniOrange, Wordpress.

Executive brief

The Login with OTP plugin for WordPress, which provides one-time password functionality for user logins, contains a security flaw that allows attackers to bypass authentication. By exploiting a lack of rate-limiting and expiration on login codes, an attacker can gain full access to any user account, including administrators. This could lead to a complete takeover of the website and theft of sensitive data.

Technical details

The vulnerability is an authentication bypass resulting from an incomplete fix for a previous security issue (CVE-2024-11178). While a rate-limit check was added to the 'otpl_login_action()' function, it was only implemented in the OTP-generation logic and not the validation logic. Furthermore, the 6-digit numeric OTPs do not expire. This allows a remote, unauthenticated attacker to perform a brute-force attack against the 900,000 possible OTP values for any user. A successful attack results in a valid authentication session via 'wp_set_auth_cookie()', granting the attacker full administrative control over the WordPress site.

Affected products

  • WordPress Login with OTP Up to, and including, 1.6

Timeline

  • 2026-05-27: advisory: NVD published the vulnerability details.

References