THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-14561 — The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user w

[NVD] CVE-2026-14561 — The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user w

mednvdPublished 2026-08-01

CVE-2026-14561 CVSS: None Published: 2026-08-01T07:16:30.410

The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including admini

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14561