PT-2025-51469 · WordPress · Wpcom Member
Wesley
·
Published
2025-12-16
·
Updated
2025-12-18
·
CVE-2025-14002
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WPCOM Member plugin for WordPress versions prior to 1.7.17
Description
The software is susceptible to authentication bypass through brute-force attacks. This is caused by a weak One-Time Password (OTP) generation process, utilizing only six numeric digits with a ten-minute validity period and lacking rate limiting on verification attempts. An attacker knowing a target’s phone number can potentially bypass authentication as any user, including administrators, if the target does not promptly notice or disregard the SMS notification containing the OTP.
Recommendations
Update the WPCOM Member plugin to version 1.7.17 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpcom Member