CVE-2025-3746 Details
Description
The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.14 to 2.0.59. This is due to the plugin not properly validating a user's identity prior to updating their details, like email. This makes it possible for unauthenticated attackers to change arbitrary users' email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. Additionally, the plugin returns authentication cookies in the response, which can be used to access the account directly.
A privilege escalation vulnerability allowing account takeover has been identified in the OTP-less One Tap Sign In plugin for WordPress, affecting versions 2.0.14 prior to 2.0.59. The vulnerability arises because the plugin fails to properly validate a user's identity before allowing changes to user details, such as email addresses. This flaw enables unauthenticated attackers to modify the email addresses of arbitrary users, including administrators. Once the email is changed, the attacker can reset the user's password and gain access to their account. Additionally, the plugin's response includes authentication cookies that can be used for direct account access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 2, 2025CISA-ADP
Assessed May 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OTP-less one tap Sign in | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 2, 2025 | New CVE Received | [email protected] |
Volerion