Security Advisory
CVE-2026-12492
9.8
CRITICAL
Vulnerability Description
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.
Published Date
July 16, 2026
Official Source
NIST NVD Advisory