The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-01 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-14561
Mitre link : CVE-2026-14561
CVE.ORG link : CVE-2026-14561
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
