PT-2026-67044 · WordPress · Authora : Easy Login With Mobile Number

·

CVE-2026-14561

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Authora : Easy login with mobile number versions prior to 1.7.7
Description The plugin fails to keep the one-time login code confidential. It returns the code and a valid verification token in the response of an unauthenticated action. This allows unauthenticated attackers to log in as any user, including administrators, provided they know the registered mobile number, or to create arbitrary accounts.
Recommendations Update Authora : Easy login with mobile number to version 1.7.7 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14561

Affected Products

Authora : Easy Login With Mobile Number