CVE-2025-10484

CRITICAL

WooCommerce <1.3.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.1. This is due to the plugin not properly verifying a users identity prior to authenticating them via the fma_lwp_set_session_php_fun() function. This makes it possible for unauthenticated attackers to authenticate as any user on the site, including administrators, without a valid password.

Scores

CVSS v3 9.8
EPSS 0.0045
EPSS Percentile 63.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-288
Status published
Products (1)
FmeAddons/Registration & Login with Mobile Phone Number for WooCommerce < 1.3.1
Published Jan 17, 2026
Tracked Since Feb 18, 2026