VYPR

Otpless

by WordPress

Source repositories

CVEs (1)

  • CVE-2025-3746CriMay 2, 2025
    risk 0.64cvss 9.8epss 0.00

    The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.14 to 2.0.59. This is due to the plugin not properly validating a user's identity prior to updating their details, like email. This makes it possible for…