Authentication vulnerability in OTP Login Woocommerce & Gravity Forms 2.2

The OTP Login Woocommerce & Gravity Forms plugin for WordPress is not secure. It is vulnerable to an attack where malicious users can bypass the authentication process. This is possible because the plugin sends login codes for administrators in an AJAX response. This means that even if the attacker doesn’t have access to the administrator’s phone number, they could still obtain the login code by using social engineering or reconnaissance.

Detected in:

OTP Login & Register Woocommerce fixed vulnerable versions:
OTP Login Woocommerce (Login with OTP) fixed vulnerable versions:
OTP Login Woocommerce & Gravity Forms fixed vulnerable versions: >= * <= 2.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.