VYPR

OTP Login & Register Woocommerce

by WordPress

CVEs (1)

  • CVE-2026-12215MedSep 11, 2026
    risk 0.34cvss 5.3epss

    The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the…