THREAT OPS › Threat News › [NVD] CVE-2026-14561 — The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user w
[NVD] CVE-2026-14561 — The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user w
CVE-2026-14561 CVSS: None Published: 2026-08-01T07:16:30.410
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including admini
Indicators of compromise
- CVE-2026-14561cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14561