PT-2026-82087 · WordPress · Classified Listing - Mobile Number Verification

·

CVE-2026-15985

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Classified Listing - Mobile Number Verification versions prior to 1.6.1
Description An authentication bypass exists due to missing server-side Firebase OTP validation within the process otp login() function. This allows unauthenticated attackers to authenticate as any user registered in the plugin's phone table by submitting an arbitrary OTP code and UID through the Firebase OTP login flow. Exploitation is possible if OTP login is enabled with Firebase as the verification gateway and the attacker knows or guesses the target account's registered phone number. This can lead to the takeover of administrator accounts if they have a registered phone number.
Recommendations Update to a version newer than 1.6.0. As a temporary mitigation, disable OTP login or switch the verification gateway from Firebase to another provider.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15985

Affected Products

Classified Listing - Mobile Number Verification