Junglewise Threat Intelligence

CVE-2026-14561: Authora Easy login with mobile number authentication bypass via OTP disclosure

CVE-2026-14561 · Severity: info · CVSS 9.8 · Published 2026-08-01

Executive brief

A vulnerability in the Authora WordPress plugin, which allows users to log in using their mobile phone numbers, could allow an attacker to take over any user account. By exploiting a flaw in how the plugin handles one-time login codes, an unauthorized person can gain full access to the website, including administrator accounts, if they know the target's mobile number. This could lead to total site compromise, data theft, or unauthorized changes to the website.

Technical details

An authentication bypass vulnerability exists in the Authora WordPress plugin due to the improper disclosure of sensitive information. The plugin returns the one-time login (OTP) code and a valid verification token directly in the HTTP response of an unauthenticated action. An attacker can trigger this action and use the leaked credentials to authenticate as any user, including administrators, provided they know the registered mobile number. The vulnerability also allows for the creation of arbitrary accounts. This issue is fixed in version 1.7.7.

Affected products

  • Authora Authora : Easy login with mobile number < 1.7.7

Timeline

  • 2026-07-20: disclosed
  • 2026-08-01: advisory: NVD publication date
  • 1.7.7: patched

References