WordPress Login With OTP Vulnerable to Authentication Bypass
CVE-2024-11178

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 December 2024

What is CVE-2024-11178?

The Login With OTP plugin for WordPress allows unauthenticated attackers to bypass authentication mechanisms due to inadequate OTP (One-Time Password) generation. This vulnerability affects versions up to and including 1.4.2, where the plugin generates weak OTPs without imposing any timeframe or validation limit. Consequently, attackers can exploit this flaw to brute-force the 6-digit numeric OTP, gaining unauthorized access to user accounts, including administrative accounts, provided they have access to the corresponding email addresses.

Affected Version(s)

Login with OTP 0 <= 1.4.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton
.