CVE-2026-15210
Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.
| Vendor | unknown |
| Product | otp login with phone number, otp verification |
| Published | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown otp login with phone number, otp verification
Be the first to know when new unknown vulnerabilities affecting unknown otp login with phone number, otp verification are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / OTP Login With Phone Number, OTP Verification
0 < 1.8.71
References
Credits
Sai Praneeth Koti WPScan