CyberRota Analysis
AI-GeneratedThe Happy Coders OTP Login for WooCommerce plugin for WordPress prior to version 2.8 is vulnerable due to a failure to properly validate one-time passwords during user authentication. This critical flaw allows unauthenticated attackers to gain access to existing user accounts, including those of administrators, and to create new accounts without authorization. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.
Original NVD Description
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.