Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force
CVE-2026-15210
Description
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.8.71
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/96101127-8b13-4770-9204-f540fb044040/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.