CVE-2026-12492: Unknown Happy Coders OTP Login For Woocommerce
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.
Affected products
- Unknown Happy Coders OTP Login For Woocommerce: from 1.5, before 2.8 (fixed in 2.8)
Published 2026-07-16. Last modified 2026-07-16.