Happy Coders OTP Login for WooCommerce

Happy Coders OTP Login for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is Authentication Bypass Using An Alternate Path Or Channel, behind 1 of the records (100%).

The one issue recorded for Happy Coders OTP Login for WooCommerce has a vendor fix available, so running the current release closes it.

All of these findings were reported by moonge. Happy Coders OTP Login for WooCommerce is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Happy Coders OTP Login for WooCommerce vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-12492

Happy Coders OTP Login for WooCommerce <= 2.7 - Unauthenticated Privilege Escalation via Account Takeover

Read the full analysis

Vulnerability Records

1 records
Happy Coders OTP Login for WooCommerce banner
Latestv2.8

Happy Coders OTP Login for WooCommerce

Happy Coders

Author

Happy Coders

5.0(7)
100/100
Last Updated
2026-06-24 (3mo ago)
Active Installs
20+
Downloads
1,734
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2025-06-26 (1y ago)

Happy Coders OTP Login is a simple, secure, and customizable OTP login plugin for WordPress and WooCommerce sites. It enables users to log in using their mobile number via one-time password (OTP) verification, using the MSG91 SMS API, and also supports email-based OTP login. The plugin supports full-screen and popup login forms, integrates smoothly with WooCommerce, and improves user experience by replacing traditional email/password logins with secure phone-based authentication. Now, you can fully customize your transactional SMS messages using dynamic variables like ##customer_name##, ##order_id##, and more, directly from the plugin settings. Watch our quick video tutorial to see how easy it is to set up! MSG91 Integration This plugin uses the MSG91 SMS and WhatsApp gateway (https://msg91.com) to send and verify OTPs, and also to send order-related notifications. You must have a valid MSG91 account and approved SMS/WhatsApp templates. You can sign up here Visit MSG91’s Terms of Service and Privacy Policy for more details about how they handle data Data Handling and Privacy Only the phone number is sent to MSG91 for OTP and transactional SMS/WhatsApp delivery. No personal or sensitive user data is stored or tracked by this plugin. Plugin does not collect analytics or track users without consent. All configurable from the plugin settings page. 🔥 Features: – Full-screen or popup OTP login form – WooCommerce login compatibility – OTP verification via MSG91 (SMS & WhatsApp) – Email OTP login option – WhatsApp Send OTP support – Automatic SMS/WhatsApp alerts for: – New user registration – Order placed – Order shipped – Order completed – Cart cronjob (abandoned cart reminders) – Customizable resend timer – Country code and flag selection – Shortcodes for embedding login anywhere – Admin panel for MSG91 and plugin settings – Customizable transactional SMS templates with dynamic variables (e.g., ##customer_name##, ##order_id##). – Dynamic OTP length (4 or 6 digits). 🎯 Shortcodes: – [msg91_otp_form] – Display full-screen OTP login form anywhere (pages, posts, widgets). 🔧 Admin Settings: – MSG91 Auth Key, Sender ID, Template IDs – Enable/disable WhatsApp OTP option – Country code options – OTP resend timer settings – Button/text color customization – Post-login redirect URL – OTP send limit per user/day – Enable/disable specific SMS/WhatsApp features (registration, order, cart) – Customizable SMS message templates with dynamic variables. Configuration Get an MSG91 Account: This plugin requires an MSG91 account. If you don’t have one, you can sign up here. Enter Credentials: In the plugin settings, enter your MSG91 Auth Key, Sender ID, and DLT-approved Template IDs. Display the Form: Use the shortcode [msg91_otp_form] on any page or add the CSS class otp-popup-trigger to a button/link to show the login form. Support We are committed to helping you succeed. To get you the fastest and most accurate help, please direct your query to the correct team. For Plugin Issues & Configuration (Happy Coders Support) If you need help with installing the plugin, configuring its settings in WordPress, encounter a bug, or have a feature request for the plugin itself, please use our official support channel. Primary Support Channel: WordPress.org Support Forum For MSG91 Service & Delivery Issues (MSG91 Support) If your question is about the MSG91 service itself—such as your account, API key, billing, Sender ID approval, DLT templates, or SMS/WhatsApp delivery reports—you must contact the MSG91 support team directly. They are the experts on their platform and can assist you with all service-related inquiries. Contact MSG91 Support: Visit the MSG91 Contact Page

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C