CVE-2025-7692

Orion Login with SMS <= 1.0.5 - Authenticated Bypass via Weak OTP

The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the olws_handle_verify_phone() function not utilizing a strong enough OTP value, exposing the hash needed to generate the OTP value, and no restrictions on the number of attempts to submit the code. This makes it possible for unauthenticated attackers to log in as other users, including administrators, if they have access to their phone number.


We have discovered 38 live websites that are affected by CVE-2025-7692.

Run a Free Instant Scan




Affected Software

Product  Orion Login With Sms
Category Wordpress Plugins
Vulnerable Domains38 live websites (100% of Orion Login With Sms install base)
Vulnerable Versions
  • from 0 through 1.0.5
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Jul 22, 2025
  • Updated - Jul 22, 2025

Credits

  • Kenneth Dunn (finder)

Website Distribution by Country

Number of websites using CVE-2025-7692
United States15 websites



India7 websites
Denmark3 websites
Germany2 websites
Israel2 websites
Netherlands2 websites
Cyprus1 websites
France1 websites
GB1 websites
Iceland1 websites

Website Distribution by TLD

Number of websites using CVE-2025-7692
.com24 websites
.com.au1 websites
.fr1 websites
.io1 websites
.it1 websites
.net1 websites
.nl1 websites

Websites affected by CVE-2025-7692

Top websites that are affected by CVE-2025-7692. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States*,***,***
*********.it Italy*,***,***
************.com India*,***,***
*************.com United States*,***,***
************.com United States*,***,***
*************.com Israel*,***,***
*********.design Netherlands**,***,***
**************.com United States**,***,***
************.fr France**,***,***
**.*********.**.il Israel**,***,***
See full domain list

FAQ

CVE-2025-7692 is Authentication Bypass Using an Alternate Path or Channel in Orion Login With Sms
A total of 38 websites have been identified as vulnerable to CVE-2025-7692, based on global website indexing conducted by WebTechSurvey.
The Orion Login With Sms is affected by the CVE-2025-7692 vulnerability.
Orion Login With Sms versions up to and including 1.0.5 are vulnerable to CVE-2025-7692.