{"id":"CVE-2026-15210","published":"2026-08-05T07:16:34.897","lastModified":"2026-08-05T16:16:50.297","description":"The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-287"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/96101127-8b13-4770-9204-f540fb044040/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to brute-force OTP codes for any account, potentially taking over administrator accounts.","exploitability":"Exploitation is relatively easy due to the lack of rate limiting or code invalidation after failed attempts.","blast_radius":"If exploited, it could lead to complete compromise of user and admin accounts on affected WordPress sites.","remediation":"Update the OTP Login With Phone Number plugin to version 1.8.71 or later immediately.","tags":["auth-bypass","brute-force","wordpress","otptoken"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:44:48.316Z"}}