WordPress security by component
Authora : Easy login with mobile number
Plugin description
Authora : Easy login with mobile number is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
authora-easy-login-with-mobile-numberLatest vulnerability
CVE-2026-14561: Authora returns the one-time code needed to log in as any known mobile user
Authora before 1.7.7 returns both a one-time login code and a valid verification token in the response to an unauthenticated action. A visitor who knows a user's registered mobile number can request those values and complete login as that user, including an Administrator, or use the same flow to create arbitrary accounts. The published record does not disclose the action, mobile-number and token parameters, response fields or verification function.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-14561
Authora returns the one-time code needed to log in as any known mobile user
Authora before 1.7.7 returns both a one-time login code and a valid verification token in the response to an unauthenticated action. A visitor who knows a user's registered mobile number can request those values and complete login as that user, including an Administrator, or use the same flow to create arbitrary accounts. The published record does not disclose the action, mobile-number and token parameters, response fields or verification function.
|
1.7.7 |
CVEPending
NVDPending
|