PT-2026-82087 · WordPress · Classified Listing - Mobile Number Verification
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Classified Listing - Mobile Number Verification versions prior to 1.6.1
Description
An authentication bypass exists due to missing server-side Firebase OTP validation within the
process otp login() function. This allows unauthenticated attackers to authenticate as any user registered in the plugin's phone table by submitting an arbitrary OTP code and UID through the Firebase OTP login flow. Exploitation is possible if OTP login is enabled with Firebase as the verification gateway and the attacker knows or guesses the target account's registered phone number. This can lead to the takeover of administrator accounts if they have a registered phone number.Recommendations
Update to a version newer than 1.6.0.
As a temporary mitigation, disable OTP login or switch the verification gateway from Firebase to another provider.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Classified Listing - Mobile Number Verification