


Perceptive Security
SOC/SIEM Consultancy

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 17:04:40
Source:
nvd.nist.gov
Web Technologies, Identity & Access
The OTP Login With Phone Number, OTP Verification WordPress plugin versions before 1.8.71 contains a critical security flaw. The plugin fails to limit the number of OTP verification attempts and does not invalidate a one-time login code after an incorrect guess. Any unauthenticated user can request a login code for any account on the system. Since the OTP is a short numeric code, attackers can brute-force it with relative ease. Successful exploitation allows complete account takeover, including administrator accounts. This vulnerability poses a severe risk to WordPress sites using this plugin. No authentication is required to exploit this vulnerability, making it highly accessible to attackers.
Technical details
Mitigation steps:
Affected products:
OTP Login With Phone Number OTP Verification WordPress plugin (before 1.8.71)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-15210
https://wpscan.com/vulnerability/96101127-8b13-4770-9204-f540fb044040/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
