Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 May 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
India-web-developer
India-web-developer login With Otp Wordpress Wordpress wordpress |
|
| Vendors & Products |
India-web-developer
India-web-developer login With Otp Wordpress Wordpress wordpress |
Wed, 27 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_login_action()` was placed only inside the OTP-generation branch and is never evaluated on the OTP-validation branch, and the generated 6-digit OTP additionally has no expiration. This makes it possible for unauthenticated attackers to brute-force the 900,000-value OTP space for any user account (including administrators) and obtain a valid `wp_set_auth_cookie()` session, leading to full site compromise. | |
| Title | Login with OTP <= 1.6 - Unauthenticated Authentication Bypass via OTP Brute Force | |
| Weaknesses | CWE-307 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-27T10:33:35.523Z
Reserved: 2026-05-16T18:34:47.484Z
Link: CVE-2026-8760
Updated: 2026-05-27T10:33:31.000Z
Status : Deferred
Published: 2026-05-27T07:16:14.927
Modified: 2026-05-27T14:50:47.627
Link: CVE-2026-8760
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:07:03Z