CVE-2026-3655: CWE-287 Improper Authentication in glboy OTP Login With Phone Number, OTP Verification
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The `idehweb_lwp_activate_through_firebase()` function validates that a Firebase OTP session is legitimate, but the `phoneNumber` returned by Firebase is never compared against the victim's stored phone number. This makes it possible for unauthenticated attackers to authenticate as any user who has a phone number stored in user meta, including administrators, by verifying their own Firebase session and supplying the victim's phone number in the same request.
AI Analysis
Technical Summary
The vulnerability in the glboy OTP Login With Phone Number, OTP Verification plugin stems from improper authentication (CWE-287) due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number in the request. The function `idehweb_lwp_activate_through_firebase()` validates the Firebase OTP session but does not verify that the phone number returned by Firebase matches the victim's stored phone number. This allows unauthenticated attackers to bypass authentication by verifying their own Firebase session and submitting the victim's phone number, effectively impersonating any user with a stored phone number, including administrators. The vulnerability affects versions 1.8.50 through 1.8.60 of the plugin. The plugin is cloud-hosted, and a patch is available to address this issue.
Potential Impact
Successful exploitation allows unauthenticated attackers to bypass authentication controls and log in as any user with a phone number stored in user metadata, including high-privilege administrator accounts. This results in full compromise of affected WordPress sites, including confidentiality, integrity, and availability impacts as reflected by the CVSS score of 9.8.
Mitigation Recommendations
Since the plugin is a cloud-hosted service, the vendor manages remediation server-side. A patch is available for this vulnerability. Users should ensure that their plugin version is updated beyond 1.8.60 or apply the vendor-provided fix as soon as possible. Check the vendor advisory for confirmation of patch deployment and further guidance. No additional mitigation steps are indicated by the vendor advisory.
CVE-2026-3655: CWE-287 Improper Authentication in glboy OTP Login With Phone Number, OTP Verification
Description
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The `idehweb_lwp_activate_through_firebase()` function validates that a Firebase OTP session is legitimate, but the `phoneNumber` returned by Firebase is never compared against the victim's stored phone number. This makes it possible for unauthenticated attackers to authenticate as any user who has a phone number stored in user meta, including administrators, by verifying their own Firebase session and supplying the victim's phone number in the same request.
CVSS v3.1
Score 9.8critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the glboy OTP Login With Phone Number, OTP Verification plugin stems from improper authentication (CWE-287) due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number in the request. The function `idehweb_lwp_activate_through_firebase()` validates the Firebase OTP session but does not verify that the phone number returned by Firebase matches the victim's stored phone number. This allows unauthenticated attackers to bypass authentication by verifying their own Firebase session and submitting the victim's phone number, effectively impersonating any user with a stored phone number, including administrators. The vulnerability affects versions 1.8.50 through 1.8.60 of the plugin. The plugin is cloud-hosted, and a patch is available to address this issue.
Potential Impact
Successful exploitation allows unauthenticated attackers to bypass authentication controls and log in as any user with a phone number stored in user metadata, including high-privilege administrator accounts. This results in full compromise of affected WordPress sites, including confidentiality, integrity, and availability impacts as reflected by the CVSS score of 9.8.
Mitigation Recommendations
Since the plugin is a cloud-hosted service, the vendor manages remediation server-side. A patch is available for this vulnerability. Users should ensure that their plugin version is updated beyond 1.8.60 or apply the vendor-provided fix as soon as possible. Check the vendor advisory for confirmation of patch deployment and further guidance. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-03-06T18:14:33.842Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6a1944d2e29bf47b50ae4c65
Added to database: 5/29/2026, 7:48:34 AM
Last enriched: 5/29/2026, 8:03:35 AM
Last updated: 5/29/2026, 7:36:06 PM
Views: 24
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.