Authentication Bypass Vulnerability in Classified Listing Mobile Number Verification Plugin for WordPress
CVE-2026-15985

8.1HIGH

What is CVE-2026-15985?

The Classified Listing - Mobile Number Verification plugin for WordPress exhibits a critical security flaw due to a lack of server-side Firebase OTP validation within the process_otp_login() function. This oversight allows unauthenticated attackers to bypass authentication and access any user account with a registered phone number by submitting arbitrary OTP codes and UIDs during the Firebase OTP login process. For successful exploitation, the OTP login feature must be enabled, necessitating the attacker to know or guess the target user’s registered phone number. This vulnerability poses a significant threat, especially if an administrator's account is compromised, potentially leading to unauthorized control over the WordPress site.

Affected Version(s)

Classified Listing - Mobile Number Verification 0 <= 1.6.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad
.