Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Glboy
Glboy otp Login With Phone Number, Otp Verification Wordpress Wordpress wordpress |
|
| Vendors & Products |
Glboy
Glboy otp Login With Phone Number, Otp Verification Wordpress Wordpress wordpress |
Fri, 29 May 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The `idehweb_lwp_activate_through_firebase()` function validates that a Firebase OTP session is legitimate, but the `phoneNumber` returned by Firebase is never compared against the victim's stored phone number. This makes it possible for unauthenticated attackers to authenticate as any user who has a phone number stored in user meta, including administrators, by verifying their own Firebase session and supplying the victim's phone number in the same request. | |
| Title | OTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Authentication Bypass via Firebase OTP Verification | |
| Weaknesses | CWE-287 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-29T10:05:49.537Z
Reserved: 2026-03-06T18:14:33.842Z
Link: CVE-2026-3655
Updated: 2026-05-29T10:05:44.880Z
Status : Deferred
Published: 2026-05-29T08:16:18.920
Modified: 2026-05-29T13:09:05.450
Link: CVE-2026-3655
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:47:29Z