SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14561

MEDIUM · CVSS 6.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Authora: Easy login with mobile number WordPress plugin versions prior to 1.7.7 expose one-time login codes and valid verification tokens in responses to unauthenticated actions, enabling attackers to log in as any user with a known registered mobile number, including administrators. This vulnerability poses a medium risk, as it can lead to unauthorized access and account creation. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-14561
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%
WordPress

Original NVD Description

The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.