Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3666 articles · 197852 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-15210PATCHED

Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force

Description

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.

Affected Products

VendorProductVersions
—otp login with phone number, otp verification0

References

  • https://wpscan.com/vulnerability/96101127-8b13-4770-9204-f540fb044040/(exploit, vdb-entry, technical-description)

Related News (1 articles)

Tier C
VulDB21d ago
CVE-2026-15210 | OTP Login With Phone Number Plugin up to 1.8.70 on WordPress improper authentication
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.8.71
PublishedAug 5, 2026
Trending Score5
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 5, 2026
Discovered by ZDM
Aug 5, 2026
Patch Available
Aug 5, 2026