WordPress Plugin Vulnerabilities

Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure

Description

The plugin does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
0xBassia
Submitter
0xBassia
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-07-20 (about 1 month ago)
Added
2026-07-20 (about 1 month ago)
Last Updated
2026-07-20 (about 1 month ago)

Other