Authentication Bypass Vulnerability in Classified Listing Mobile Number Verification Plugin for WordPress
CVE-2026-15985
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 August 2026
What is CVE-2026-15985?
The Classified Listing - Mobile Number Verification plugin for WordPress exhibits a critical security flaw due to a lack of server-side Firebase OTP validation within the process_otp_login() function. This oversight allows unauthenticated attackers to bypass authentication and access any user account with a registered phone number by submitting arbitrary OTP codes and UIDs during the Firebase OTP login process. For successful exploitation, the OTP login feature must be enabled, necessitating the attacker to know or guess the target user’s registered phone number. This vulnerability poses a significant threat, especially if an administrator's account is compromised, potentially leading to unauthorized control over the WordPress site.
Affected Version(s)
Classified Listing - Mobile Number Verification 0 <= 1.6.0