Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical2
High1
Medium0
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-08-05

CVE-2026-15210 - Otp Verification Plugin

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.

PLUGIN Otp Verification

CVE-2026-15210

CRITICAL CVSS 9.1 2026-08-05
Threat Entry Updated 2026-07-21

CVE-2026-3655 - Otp Verification Plugin

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The `idehweb_lwp_activate_through_firebase()` function validates that a Firebase OTP session is legitimate, but the `phoneNumber` returned by Firebase is never compared against the victim's stored phone number. This makes it possible for unauthenticated attackers to authenticate as any user who has a phone number…

PLUGIN Otp Verification

CVE-2026-3655

CRITICAL CVSS 9.8 2026-05-29
Threat Entry Updated 2025-08-15

CVE-2025-8342 - Otp Verification Plugin

The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value checking in the lwp_ajax_register function in all versions up to, and including, 1.8.47. This makes it possible for unauthenticated attackers to bypass OTP verification and gain administrative access to any user account with a configured phone number by exploiting improper Firebase API error handling when the Firebase API key is not configured.

PLUGIN Otp Verification

CVE-2025-8342

HIGH CVSS 8.1 2025-08-15
Scroll to top