WordPress Login With OTP Vulnerable to Authentication Bypass
CVE-2024-11178
8.1HIGH
What is CVE-2024-11178?
The Login With OTP plugin for WordPress allows unauthenticated attackers to bypass authentication mechanisms due to inadequate OTP (One-Time Password) generation. This vulnerability affects versions up to and including 1.4.2, where the plugin generates weak OTPs without imposing any timeframe or validation limit. Consequently, attackers can exploit this flaw to brute-force the 6-digit numeric OTP, gaining unauthorized access to user accounts, including administrative accounts, provided they have access to the corresponding email addresses.
Affected Version(s)
Login with OTP 0 <= 1.4.2