PT-2026-44756 · WordPress · Login With Phone Number
Lucky_Buddy
·
Published
2026-05-29
·
Updated
2026-06-04
·
CVE-2026-3655
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OTP Login With Phone Number, OTP Verification plugin for WordPress versions 1.8.50 through 1.8.60
Description
An authentication bypass exists due to the Firebase verification flow in the 'lwp ajax register' AJAX handler not binding the Firebase session to the phone number supplied in the request. The
idehweb lwp activate through firebase() function validates the legitimacy of a Firebase OTP session, but it fails to compare the phoneNumber returned by Firebase against the victim's stored phone number. This allows unauthenticated attackers to authenticate as any user with a phone number stored in user meta, including administrators, by verifying their own Firebase session and providing the victim's phone number in the request.Recommendations
Update the plugin to a version later than 1.8.60.
As a temporary workaround, restrict access to the 'lwp ajax register' AJAX handler to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Login With Phone Number