What is CVE-2026-14561?
CVE-2026-14561: A critical flaw in the Authora: Easy login with mobile number WordPress plugin before version 1.7.7 exposes the one-time login code and a valid verification token in unauthenticated responses. This allows unauthenticated attackers to log in as any user with a registered mobile number. Immediate update to version 1.7.7 or higher is required to mitigate the risk.
Azərbaycanca: CVE-2026-14561: Authora: Easy login with mobile number WordPress plaginində 1.7.7 versiyasından əvvəl kritik boşluq aşkarlanıb. Plagin birdəfəlik giriş kodunu məxfi saxlamır və autentifikasiya olunmamış sorğulara kodu və tokeni geri qaytarır, bu da hücumçulara qeydiyyatdan keçmiş hər hansı bir istifadəçi kimi daxil olmağa imkan verir. Təhlükəsizlik üçün plagini dərhal 1.7.7 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the Authora plugin are affected by CVE-2026-14561?
This vulnerability affects all versions of the Authora: Easy login with mobile number plugin prior to version 1.7.7.
What can an attacker achieve by exploiting CVE-2026-14561?
An unauthenticated attacker can log in as any user with a registered mobile number.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.