VYPR

OTP Login Woocommerce & Gravity Forms

by WordPress

CVEs (1)

  • CVE-2023-2706HigMay 17, 2023
    risk 0.53cvss 8.1epss 0.02

    The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it…