OTP Login With Phone Number, OTP Verification
OTP Login With Phone Number, OTP Verification is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 9.1.
otp-login-with-phone-number-otp-verificationCVE-2026-15210: OTP Login permits unauthenticated code brute force and account takeover
OTP Login With Phone Number, OTP Verification before 1.8.71 lets an unauthenticated visitor request a short numeric login code for an arbitrary account, does not rate-limit verification attempts and does not invalidate the code after an incorrect guess. An attacker can repeatedly guess the OTP and then log in as the targeted user, including an administrator. This unscored record received deeper review because it exposes an unauthenticated authentication-bypass path. The CNA does not disclose the request endpoints, actions or parameter names.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-15210
OTP Login permits unauthenticated code brute force and account takeover
OTP Login With Phone Number, OTP Verification before 1.8.71 lets an unauthenticated visitor request a short numeric login code for an arbitrary account, does not rate-limit verification attempts and does not invalidate the code after an incorrect guess. An attacker can repeatedly guess the OTP and then log in as the targeted user, including an administrator. This unscored record received deeper review because it exposes an unauthenticated authentication-bypass path. The CNA does not disclose the request endpoints, actions or parameter names.
|
1.8.71 |
CVE9.1
NVDPending
|