SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-12492

CRITICAL · CVSS 9.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Happy Coders OTP Login for WooCommerce plugin for WordPress prior to version 2.8 is vulnerable due to a failure to properly validate one-time passwords during user authentication. This critical flaw allows unauthenticated attackers to gain access to existing user accounts, including those of administrators, and to create new accounts without authorization. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.

CVE
CVE-2026-12492
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%
WordPress

Original NVD Description

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.