OTP Login With Phone Number, OTP Verification

OTP Login With Phone Number, OTP Verification has 15 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 15 are fixed as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 9.8 out of 10. Severity breakdown: 3 critical and 5 high. 2024 was the busiest year with 8 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (20%). Other recurring categories include Missing Authorization, Authentication Bypass Using An Alternate Path Or Channel.

Every one of the 15 issues recorded for OTP Login With Phone Number, OTP Verification has a vendor fix available, so running the current release closes all known holes.

11 independent researchers contributed these findings, most of them (3) reported by István Márton. OTP Login With Phone Number, OTP Verification is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891006.08.2020Today16.02.20226.5Login with phone number <= 1.3.6 - Unauthenticated Remote Plugin Deletion CVSS 6.5 · 16.02.202205.07.20225.5Login with phone number <= 1.3.7 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 5.5 · 05.07.202212.01.20236.1Login with phone number <= 1.4.2 - Reflected Cross-Site Scripting CVSS 6.1 · 12.01.202312.09.20238.8Login with phone number <= 1.5.6 - Cross-Site Request Forgery to User Password Change CVSS 8.8 · 12.09.202310.04.20244.3Login with phone number <= 1.6.93 - Cross-Site Request Forgery CVSS 4.3 · 10.04.202415.04.20248.8Login with phone number <= 1.7.16 - Unauthorized Account Password Change to Privilege Escalation CVSS 8.8 · 15.04.202422.04.20245.3Login with phone number <= 1.6.93 - Missing Authorization CVSS 5.3 · 22.04.202403.05.20244.3Login with phone number <= 1.7.18 - Missing Authorization CVSS 4.3 · 03.05.202428.05.20249.8Login with phone number <= 1.7.26 - Authentication Bypass due to Missing Empty Value Check CVSS 9.8 · 28.05.202418.06.20248.1Login with phone number <= 1.7.34 - Insecure Password Reset Mechanism CVSS 8.1 · 18.06.202428.06.20244.4Login with phone number <= 1.7.35 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 28.06.202414.09.20248.8Login with phone number <= 1.7.49 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation CVSS 8.8 · 14.09.202414.08.20258.1WooCommerce OTP Login With Phone Number, OTP Verification <= 1.8.47 - Authentication Bypass CVSS 8.1 · 14.08.202528.05.20269.8OTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Authentication Bypass via Firebase OTP Verification CVSS 9.8 · 28.05.202606.08.20269.8OTP Login With Phone Number, OTP Verification <= 1.8.70 - OTP Brute Force CVSS 9.8 · 06.08.2026

Strategic Overview

Avg CVSSHigh
7.2/ 10
Patch Coverage100%
Open

0

Fixed

15

Get automatic notifications for all OTP Login With Phone Number, OTP Verification vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-65570

OTP Login With Phone Number, OTP Verification <= 1.8.70 - OTP Brute Force

Read the full analysis

Vulnerability Records

15 records
2026-08-06 00:00CVE-2026-65570
9.8
Critical
she11fYes
2026-05-28 17:56CVE-2026-3655
9.8
Critical
lucky_buddyYes
2025-08-14 13:55CVE-2025-8342
8.1
High
Arkadiusz HydzikYes
2024-09-14 00:06CVE-2024-6482
8.8
High
Thanh Nam TranYes
2024-06-28 00:00CVE-2024-37429
4.4
Medium
LuxF0zYes
2024-06-18 00:00CVE-2024-6125
8.1
High
István MártonYes
2024-05-28 00:00CVE-2024-5150
9.8
Critical
István MártonYes
2024-05-03 00:00CVE-2024-34371
4.3
Medium
Dhabaleshwar DasYes
2024-04-22 00:00CVE-2024-32832
5.3
Medium
Majed RefaeaYes
2024-04-15 00:00CVE-2024-32507
8.8
High
Emili CastellsYes
Showing 1–10 of 15 reports
OTP Login With Phone Number, OTP Verification banner
Latestv1.8.72

OTP Login With Phone Number, OTP Verification

Hamid Alinia

Author

Hamid Alinia

4.9(81)
98/100
Last Updated
2026-08-21 (22d ago)
Active Installs
900+
Downloads
137,474
Requires WP
5.9+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2020-08-06 (6y ago)

OTP Login With Phone Number lets your users login and register using their mobile phone number — no password required. Send a One-Time Password (OTP) via SMS or Firebase and authenticate instantly. Works seamlessly with WordPress and is fully compatible with WooCommerce login, registration, and checkout pages. Supports 20+ SMS gateways and lets you connect any custom SMS provider for free. 🔑 KEY FEATURES (FREE) Phone number login & registration — replace or extend the default WordPress login OTP via SMS or Firebase — free Firebase integration included Compatible with WooCommerce — works on My Account, checkout, and registration pages Compatible with LearnPress — OTP login on course checkout pages Email login — let users login with email + OTP (no password) Country flags & auto country code detection Passwordless login — frictionless UX, higher conversion rates Redirect after login/register to any URL Page protection — restrict pages to logged-in users only Password recovery via phone number OTP Existing user sync — match phone numbers already stored in user meta (e.g. WooCommerce billing phone) Store phone with or without country code Custom gateway — connect any SMS provider yourself via URL + JSON config GDPR-compliant Translation-ready — includes Persian (fa_IR), compatible with WPML & Polylang Multisite support Shortcodes for embedding login form anywhere Custom CSS support 📱 FREE SMS GATEWAYS Firebase — free OTP via Google Firebase (recommended for international sites) Twilio — international SMS gateway, free to configure Netgsm — Turkey SMS gateway Kavenegar — popular Iranian SMS gateway DrPayamak — Iranian SMS gateway Custom API — connect any SMS gateway using your own URL, headers, and body config 📱 PRO SMS GATEWAYS WhatsApp via UltraMessage Telegram MSG91 (India) Alibabacloud MessageBird Trustsignal Taqnyat (Arabic) 2Factor Textlocal Vonage SMS.ir MelliPayamak FarazSMS 🔌 COMPATIBLE WITH WooCommerce login, registration & checkout LearnPress course checkout Woodmart Theme sidebar login Elementor (via shortcode) WPForms (via shortcode) Contact Form 7 (via shortcode) WPBakery, Divi, Gutenberg (via shortcode) WPML & Polylang (translation-ready) ⚡ USE CASES eCommerce stores — reduce cart abandonment with frictionless phone login WooCommerce shops — phone-verified checkout without passwords Membership sites — verified user registration via OTP LMS platforms — secure student login for online courses Booking sites — quick login without password Any site wanting to reduce fake registrations and improve security 🚀 PRO VERSION Unlock advanced features with the Pro version: 15+ additional SMS gateways (Twilio, WhatsApp, Telegram, MSG91, and more) Advanced form builder & UI customization Custom registration fields Default user role assignment Custom gateway development support Priority support 📄 SHORTCODES [idehweb_lwp] — embed the login/register form anywhere [idehweb_lwp_metas phone_number="true" email="true"] — show logged-in user's phone/email [idehweb_lwp_verify_email] — email verification form 📚 Documentation & Support Full Documentation GitHub Repository Report Security Bug External Services This plugin uses the following external services: Firebase Authentication (optional — only when Firebase gateway is selected) – Verifies phone numbers via OTP – Data sent: phone number, IP address – Terms | Privacy Crisp Chat (optional, can be disabled in Settings > Installation) – Live chat support inside the plugin admin panel – Data sent: chat messages, name, email, IP address – Terms | Privacy Microsoft Clarity (optional, can be disabled in Settings > Installation) – Anonymous usage analytics on the plugin admin pages only. No visitor or frontend data collected. – Terms | Privacy

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C