WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in OTP Login With Phone Number, OTP Verification

Passwordless OTP login for WordPress. Login or register with phone number via SMS or Firebase. Compatible with WooCommerce. GDPR-compliant.

15Reported vulnerabilities
9.8Highest CVSS score
1.8.71Latest version
900+Active installs

What to do now

Update OTP Login With Phone Number, OTP Verification to 1.8.71 or later. 15 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 22, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-23492 High 8.8 57.1% Before 1.4.2 1.4.2 January 20, 2023
CVE-2022-0593 Medium 6.5 1.4% Before 1.3.7 1.3.7 March 14, 2022
CVE-2024-5150 Critical 9.8 0.8% 0 to 1.7.26 (inclusive) 1.7.27 May 29, 2024
CVE-2026-3655 Critical 9.8 0.5% 1.8.50 to 1.8.60 (inclusive) 1.8.61 May 29, 2026
CVE-2026-65570 Critical 9.8 0.2% 1.8.70 and earlier 1.8.71 August 6, 2026
CVE-2024-6482 High 8.8 0.5% 1.7.40 up to (but not including) 1.7.50 1.7.50 September 14, 2024
CVE-2024-32507 High 8.8 0.5% 1.7.16 and earlier 1.7.17 April 15, 2024
CVE-2023-4916 High 8.8 0.3% 1.5.6 and earlier 1.5.7 September 13, 2023
CVE-2022-0598 Medium 4.8 0.7% 1.3.7 and earlier 1.3.8 August 1, 2022
CVE-2025-8342 High 8.1 0.6% 0 to 1.8.47 (inclusive) 1.8.48 August 15, 2025
CVE-2024-6125 High 8.1 0.5% 0 to 1.7.34 (inclusive) 1.7.35 June 19, 2024
CVE-2024-32832 Medium 5.3 0.4% 1.6.93 and earlier 1.6.94 April 22, 2024
CVE-2024-37429 Medium 4.4 0.3% 1.7.35 and earlier 1.7.36 June 28, 2024
CVE-2024-34371 Medium 4.3 0.4% 1.7.18 and earlier 1.7.20 May 3, 2024
CVE-2024-31424 Medium 4.3 0.3% 1.6.93 and earlier 1.6.94 April 10, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.