PT-2026-44756 · WordPress · Login With Phone Number

Lucky_Buddy

·

Published

2026-05-29

·

Updated

2026-06-04

·

CVE-2026-3655

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OTP Login With Phone Number, OTP Verification plugin for WordPress versions 1.8.50 through 1.8.60
Description An authentication bypass exists due to the Firebase verification flow in the 'lwp ajax register' AJAX handler not binding the Firebase session to the phone number supplied in the request. The idehweb lwp activate through firebase() function validates the legitimacy of a Firebase OTP session, but it fails to compare the phoneNumber returned by Firebase against the victim's stored phone number. This allows unauthenticated attackers to authenticate as any user with a phone number stored in user meta, including administrators, by verifying their own Firebase session and providing the victim's phone number in the request.
Recommendations Update the plugin to a version later than 1.8.60. As a temporary workaround, restrict access to the 'lwp ajax register' AJAX handler to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3655

Affected Products

Login With Phone Number