---
id: CVE-2026-14561
title: >-
  The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does
  not keep its one-time login code confidential, returning the code and a valid
  verification token in the response of an unauthenticated action, allowing
  unauth…
summary: >-
  The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does
  not keep its one-time login code confidential, returning the code and a valid
  verification token in the response of an unauthenticated action, allowing
  unauth…
severity: none
published: '2026-08-01'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14561'
references:
  - url: 'https://wpscan.com/vulnerability/4025601f-ed33-4772-b716-a9979830e10d/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00275
epssPercentile: 0.17753
ingestedAt: '2026-08-02T05:17:47.124Z'
---

## Overview

The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
