PT-2026-67044 · WordPress · Authora : Easy Login With Mobile Number
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Authora : Easy login with mobile number versions prior to 1.7.7
Description
The plugin fails to keep the one-time login code confidential. It returns the code and a valid verification token in the response of an unauthenticated action. This allows unauthenticated attackers to log in as any user, including administrators, provided they know the registered mobile number, or to create arbitrary accounts.
Recommendations
Update Authora : Easy login with mobile number to version 1.7.7 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Authora : Easy Login With Mobile Number