CVE-2025-3746
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/05/2025
Last modified:
02/05/2025
Description
The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.14 to 2.0.59. This is due to the plugin not properly validating a user&#39;s identity prior to updating their details, like email. This makes it possible for unauthenticated attackers to change arbitrary users&#39; email addresses, including administrators, and leverage that to reset the user&#39;s password and gain access to their account.<br />
Additionally, the plugin returns authentication cookies in the response, which can be used to access the account directly.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL