Xootix · Otp Login & Register Woocommerce · CVE-2026-12215
The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process otp form` is keyed exclusively on the attacker-controlled `xoo ml user ip data` cookie's `ip address` field, allowing unlimited counter resets by simply rotating the cookie, while the OTP itself is generated with PHP's non-cryptographic `rand()` function over a default space of only 9,000 possible values (1000–9999), and both the OTP issuance endpoint (`xoo ml login with otp`) and verification endpoint (`xoo ml otp form submit`) are registered as unauthenticated `wp ajax nopriv` actions with no nonce or capability checks. This makes it possible for unauthenticated attackers to brute-force the OTP for any registered account and obtain a full WordPress authentication session — including for administrator accounts — via `wp set auth cookie()` in `login user with otp()`. Exploitation requires the attacker to know the target user's registered phone number, which is used to trigger OTP issuance via the unauthenticated `xoo ml login with otp` endpoint.