The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and including, 1.7.16. This is due to weak OTP (One-Time Password) generation using only 6 numeric digits combined with a 10-minute validity window and no rate limiting on verification attempts. This makes it possible for unauthenticated attackers to brute-force the verification code and authenticate as any user, including administrators, if they know the target's phone number, and the target does not notice or ignores the SMS notification with the OTP.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpcom Wpcom wpcom Member |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpcom Wpcom wpcom Member |
Tue, 16 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and including, 1.7.16. This is due to weak OTP (One-Time Password) generation using only 6 numeric digits combined with a 10-minute validity window and no rate limiting on verification attempts. This makes it possible for unauthenticated attackers to brute-force the verification code and authenticate as any user, including administrators, if they know the target's phone number, and the target does not notice or ignores the SMS notification with the OTP. | |
| Title | WPCOM Member <= 1.7.16 - Authentication Bypass via Weak OTP | |
| Weaknesses | CWE-287 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-16T14:58:11.381Z
Reserved: 2025-12-04T02:28:05.914Z
Link: CVE-2025-14002
Updated: 2025-12-16T14:57:05.380Z
Status : Awaiting Analysis
Published: 2025-12-16T10:15:42.583
Modified: 2025-12-16T14:10:11.300
Link: CVE-2025-14002
No data.