CVE-2026-15210 PUBLISHED

Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force

Assigner: WPScan
Reserved: 09.07.2026 Published: 05.08.2026 Updated: 05.08.2026

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.

Product Status

Vendor Unknown
Product OTP Login With Phone Number, OTP Verification
Versions Default: unaffected
  • affected from 0 to 1.8.71 (excl.)

Credits

  • Sai Praneeth Koti finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE