Feed/CVE-2026-12492
CVE-2026-12492CRITICALCVSS 9.8

CVE-2026-12492

Published Jul 16, 2026·Updated Jul 16, 2026

NVD Description

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free