CVE-2026-8760Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_login_action()` was placed only inside the OTP-generation branch and is never evaluated on the OTP-validation branch, and the generated 6-digit OTP additionally has no expiration. This makes it possible for unauthenticated attackers to brute-force the 900,000-value OTP space for any user account (including administrators) and obtain a valid `wp_set_auth_cookie()` session, leading to full site compromise.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-27: 2Patch / Workaround · 2026-05-27: 2Technical Details · 2026-05-27: 205-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-8760 — CVSS 9.8/10 ██████████ The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including,... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/VGVTPJTybn

    Post summary

    The tweet announces a critical authentication bypass in the Login with OTP WordPress plugin (CVE-2026-8760), citing a CVSS of 9.8/10 and urging users to patch immediately.

    1000091
    43 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-8760 (CVSS 9.8) impacts the Login with OTP WordPress plugin up to v1.6 with an authentication bypass. Organizations using this plugin should verify versions and apply updates or alternatives. https://nvd.nist.gov/vuln/detail/CVE-2026-8760 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning

    Post summary

    The tweet announces CVE-2026-8760, an authentication bypass in the Login with OTP WordPress plugin up to v1.6, with a CVSS score of 9.8, and advises checking versions and applying updates or alternatives.

    0000039
    81 followersView on X

Explore more