Authentication Bypass Vulnerability in WPCOM Member Plugin for WordPress
CVE-2025-14002
8.1HIGH
What is CVE-2025-14002?
The WPCOM Member plugin for WordPress is susceptible to an authentication bypass due to a weakness in its one-time password (OTP) generation mechanism. The plugin uses a six-digit numeric OTP, which combined with a limited validity period of only 10 minutes and the absence of rate limiting on verification attempts, creates a significant security risk. Attackers can exploit this flaw by brute-forcing the OTP if they have access to the user's phone number. If the target does not notice or ignore the SMS alert containing the OTP, unauthorized users could potentially gain access to the account, including administrator privileges.
Affected Version(s)
WPCOM Member * <= 1.7.16