CVE Explorer
CVE-2026-3655
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The `idehweb_lwp_activate_through_firebase()` function validates that a Firebase OTP session is legitimate, but the `phoneNumber` returned by Firebase is never compared against the victim's s
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"OTP Login With Phone Number, OTP Verification","vendor":"glboy","versions":[{"lessThanOrEqual":"1.8.60","status":"affected","version":"1.8.50","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2b809053d25adbd1c0e6b2a2ac7c0b64b05ab7d41f66286e43f1d3d1842e14b7 · sha256:b92f0e46148f5d7b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2b809053d25adbd1c0e6b2a2ac7c0b64b05ab7d41f66286e43f1d3d1842e14b7 · sha256:b92f0e46148f5d7b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-287","description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2b809053d25adbd1c0e6b2a2ac7c0b64b05ab7d41f66286e43f1d3d1842e14b7 · sha256:b92f0e46148f5d7b… · /containers/cna/problemTypes/0/descriptions/0
Source references
6 source assertions{"url":"https://plugins.trac.wordpress.org/browser/login-with-phone-number/tags/1.8.60/inc/ajax-handlers.php#L1167"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2b809053d25adbd1c0e6b2a2ac7c0b64b05ab7d41f66286e43f1d3d1842e14b7 · sha256:b92f0e46148f5d7b… · /containers/cna/references/3
{"url":"https://plugins.trac.wordpress.org/browser/login-with-phone-number/tags/1.8.60/inc/ajax-handlers.php#L649"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2b809053d25adbd1c0e6b2a2ac7c0b64b05ab7d41f66286e43f1d3d1842e14b7 · sha256:b92f0e46148f5d7b… · /containers/cna/references/1
{"url":"https://plugins.trac.wordpress.org/browser/login-with-phone-number/tags/1.8.60/inc/ajax-handlers.php#L659"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2b809053d25adbd1c0e6b2a2ac7c0b64b05ab7d41f66286e43f1d3d1842e14b7 · sha256:b92f0e46148f5d7b… · /containers/cna/references/2
{"url":"https://plugins.trac.wordpress.org/browser/login-with-phone-number/trunk/inc/ajax-handlers.php#L649"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2b809053d25adbd1c0e6b2a2ac7c0b64b05ab7d41f66286e43f1d3d1842e14b7 · sha256:b92f0e46148f5d7b… · /containers/cna/references/4
{"url":"https://plugins.trac.wordpress.org/changeset/3479314/login-with-phone-number/trunk/inc/ajax-handlers.php?old=3455810&old_path=login-with-phone-number%2Ftrunk%2Finc%2Fajax-handlers.php"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2b809053d25adbd1c0e6b2a2ac7c0b64b05ab7d41f66286e43f1d3d1842e14b7 · sha256:b92f0e46148f5d7b… · /containers/cna/references/5
{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7fc410f2-5f2b-4eea-a0fb-fe58f988f95f?source=cve"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2b809053d25adbd1c0e6b2a2ac7c0b64b05ab7d41f66286e43f1d3d1842e14b7 · sha256:b92f0e46148f5d7b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.