๐Ÿ” CVE Alert

CVE-2026-14561

UNKNOWN 0.0

Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.

Vendor unknown
Product authora : easy login with mobile number
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown authora : easy login with mobile number

Be the first to know when new unknown vulnerabilities affecting unknown authora : easy login with mobile number are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Authora : Easy login with mobile number
0 < 1.7.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4025601f-ed33-4772-b716-a9979830e10d/

Credits

0xBassia WPScan