{"id":"CVE-2026-15210","published":"2026-08-05T07:16:34.897","lastModified":"2026-08-05T16:16:50.297","description":"The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-287"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/96101127-8b13-4770-9204-f540fb044040/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to brute-force OTP codes, potentially taking over any account, including administrator accounts.","exploitability":"Exploitation is relatively easy due to the lack of rate limiting or code invalidation after failed attempts.","blast_radius":"If exploited, the attacker could gain full control over the WordPress site, including administrator privileges.","remediation":"Upgrade to version 1.8.71 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","brute-force","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:10:58.889Z"}}