CVE-2026-15210
9.1 CRITICALPublished 2026-08-05 · Updated 2026-08-05
AI risk analysis
- Summary
- The flaw allows unauthenticated users to brute-force OTP codes, potentially taking over any account, including administrator accounts.
- Exploitability
- Exploitation is relatively easy due to the lack of rate limiting or code invalidation after failed attempts.
- Blast radius
- If exploited, the attacker could gain full control over the WordPress site, including administrator privileges.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to version 1.8.71 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-287
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-85734PoC
- HIGHCVE-2026-100871PoC
- CRITICALCVE-2026-101077PoC
- HIGHCVE-2026-15372
- HIGHCVE-2026-16036
- MEDIUMCVE-2026-61630PoC
- HIGHCVE-2026-61687PoC
- CRITICALCVE-2026-63456
Related by shared AI tags and CWE weakness class. Browse the full archive.