CVE-2024-12857

CRITICAL

AdForest < 5.1.8 - Unauthenticated Authentication Bypass via OTP Login

Title source: llm
STIX 2.1

Description

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number.

Scores

CVSS v3 9.8
EPSS 0.0072
EPSS Percentile 48.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306 CWE-288
Status published
Products (2)
scriptsbundle/AdForest < 5.1.8
scriptsbundle/adforest < 5.1.9
Published Jan 22, 2025
Tracked Since Feb 18, 2026