Authentication Bypass Vulnerability in WPCOM Member Plugin for WordPress
CVE-2025-14002
What is CVE-2025-14002?
The WPCOM Member plugin for WordPress is susceptible to an authentication bypass due to a weakness in its one-time password (OTP) generation mechanism. The plugin uses a six-digit numeric OTP, which combined with a limited validity period of only 10 minutes and the absence of rate limiting on verification attempts, creates a significant security risk. Attackers can exploit this flaw by brute-forcing the OTP if they have access to the user's phone number. If the target does not notice or ignore the SMS alert containing the OTP, unauthorized users could potentially gain access to the account, including administrator privileges.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPCOM Member * <= 1.7.16
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved