๐Ÿ” CVE Alert

CVE-2026-15210

UNKNOWN 0.0

Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.

Vendor unknown
Product otp login with phone number, otp verification
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for unknown otp login with phone number, otp verification

Be the first to know when new unknown vulnerabilities affecting unknown otp login with phone number, otp verification are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / OTP Login With Phone Number, OTP Verification
0 < 1.8.71

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/96101127-8b13-4770-9204-f540fb044040/

Credits

Sai Praneeth Koti WPScan