CVE-2026-107638: pH7Builder before 18.5.0 2FA Brute Force via VerificationCodeFormProcess.php
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper restriction of authentication attempts vulnerability that allows attackers to bypass two-factor authentication by guessing TOTP codes without limits. Attackers who know an account password can submit unlimited 6-digit verification codes to VerificationCodeFormProcess.php to take over member, affiliate, or administrator accounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pH7Builderto a version that resolves this vulnerability.Fixed in 18.5.0
Event History
Frequently Asked Questions
Which accounts are at risk?
Member, affiliate, and administrator accounts are in scope. An attacker can take over an account if they know its password and can successfully guess the account's TOTP verification code.
What does an attacker need to exploit this issue?
The attacker needs a valid account password. They can then submit repeated six-digit verification-code guesses to the affected verification-code processing endpoint without attempt limits.
How can I tell whether my deployment is affected?
Deployments running pH7Builder versions earlier than 18.5.0 are affected. The vulnerable code path is VerificationCodeFormProcess.php in the two-factor-auth module.
What is the available remediation?
Upgrade pH7Builder to version 18.5.0 or later. The provided fix reference is commit 44970860b82f8af867de9d2832081485f5dbe578.