← WordPress Vulnerabilities
WordPress security by component

OTP Login With Phone Number, OTP Verification

OTP Login With Phone Number, OTP Verification is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 9.1.

Plugin slug: otp-login-with-phone-number-otp-verification

CVE-2026-15210: OTP Login permits unauthenticated code brute force and account takeover

OTP Login With Phone Number, OTP Verification before 1.8.71 lets an unauthenticated visitor request a short numeric login code for an arbitrary account, does not rate-limit verification attempts and does not invalidate the code after an incorrect guess. An attacker can repeatedly guess the OTP and then log in as the targeted user, including an administrator. This unscored record received deeper review because it exposes an unauthenticated authentication-bypass path. The CNA does not disclose the request endpoints, actions or parameter names.

PublishedAug 05, 2026
Known safe version1.8.71
Published vulnerabilities for otp-login-with-phone-number-otp-verification
Safe version
Aug 05, 2026 CVE-2026-15210
OTP Login permits unauthenticated code brute force and account takeover
OTP Login With Phone Number, OTP Verification before 1.8.71 lets an unauthenticated visitor request a short numeric login code for an arbitrary account, does not rate-limit verification attempts and does not invalidate the code after an incorrect guess. An attacker can repeatedly guess the OTP and then log in as the targeted user, including an administrator. This unscored record received deeper review because it exposes an unauthenticated authentication-bypass path. The CNA does not disclose the request endpoints, actions or parameter names.
1.8.71
CVE9.1
NVDPending