CVE-2026-15985CWE-289

CVE-2026-15985

High · published August 26, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
25.1
In the wild
Unconfirmed
What it is

The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is due to missing server-side Firebase OTP validation in the process_otp_login() function. This makes it possible for unauthenticated attackers to authenticate as any user with a phone number registered in the plugin's phone table by submitting an arbitrary OTP code and UID through the Firebase OTP login flow. Successful exploitation requires OTP login to be enabled with Firebase selected as the verification gateway, and requires the attacker to know or guess the target account's registered phone number. Administrator account takeover is possible if an administrator account has a phone number registered in the plugin.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00325 · 25.1th percentile
Weakness
CWE-289 · Authentication Bypass by Alternate Name
Published
2026-08-26T16:16Z
References (2)
EPSS history
Timeline
  • 28 AUG 06:31Z
    EPSS moved — → 0%
    epss
  • 26 AUG 11:36Z
    Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login
    cvelistv5