Security Advisory

CVE-2026-12492

9.8
CRITICAL

Vulnerability Description

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.
Published Date July 16, 2026
Official Source NIST NVD Advisory