CVE-2026-15210
Received Received - Intake

Brute-Forceable OTP Login in WordPress Plugin

Vulnerability report for CVE-2026-15210, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: WPScan

Description

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpplugins login_signup_with_phone_number_otp_verification to 1.8.71 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the WordPress plugin 'Login/Signup with Phone Number, OTP Verification' before version 1.8.71. It allows unauthenticated attackers to request OTP login codes for any account and brute-force short numeric codes to gain unauthorized access, including to administrator accounts.

Detection Guidance

Check if the WordPress plugin 'Login/Signup with Phone Number, OTP Verification' is installed and verify its version. If the version is below 1.8.71, the system is vulnerable. Monitor login attempts for repeated OTP failures or unusual brute-force patterns.

Impact Analysis

An attacker could take over any account on your WordPress site, including admin accounts, by guessing the OTP code. This could lead to full site compromise, data theft, or malicious actions being performed on your behalf.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating compliance requirements for data protection standards like GDPR and HIPAA, which mandate strict access controls and protection of personal information.

Mitigation Strategies

Update the plugin to version 1.8.71 or later immediately. Implement rate limiting on OTP requests and enforce account lockouts after multiple failed attempts. Review server logs for suspicious login activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15210. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart