What is CVE-2026-15210?
Found in the ’OTP Login With Phone Number’ WordPress plugin before version 1.8.71, this flaw allows an unauthenticated user unlimited OTP attempts and enables requesting a login code for any account. The short numeric code creates a brute force risk, so immediately updating the plugin is recommended.
Azərbaycanca: CVE-2026-15210 'OTP Login With Phone Number' WordPress plugin-inin 1.8.71-dən əvvəlki versiyalarında aşkarlanıb. Zəiflik autentifikasiya olunmamış şəxsə limitsiz OTP cəhdi etməyə və istənilən hesab üçün birdəfəlik giriş kodu tələb etməyə imkan verir. Qısa rəqəmli kod olduğu üçün brute force hücumu riski var, plugin-i dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the OTP Login With Phone Number plugin are affected by CVE-2026-15210?
The vulnerability affects versions of the plugin prior to 1.8.71.
What can an attacker do by exploiting this flaw?
An unauthenticated user can make unlimited OTP attempts and request a login code for any account.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.