Unauthorized Logins via OTP Validation Bypass
CVE-2024-9861
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 October 2024
What is CVE-2024-9861?
The Miniorange OTP Verification with Firebase plugin for WordPress is susceptible to an authentication bypass issue present in versions up to and including 3.6.0. This vulnerability arises from inadequate validation of the token supplied during the one-time password (OTP) login process. As a result, attackers lacking valid credentials can exploit this weakness to gain unauthorized access to accounts, potentially including administrative privileges, by simply knowing the associated phone number of a targeted user.
Affected Version(s)
Miniorange OTP Verification with Firebase 0 <= 3.6.0