CyberRota Analysis
AI-GeneratedThe Authora: Easy login with mobile number WordPress plugin versions prior to 1.7.7 expose one-time login codes and valid verification tokens in responses to unauthenticated actions, enabling attackers to log in as any user with a known registered mobile number, including administrators. This vulnerability poses a medium risk, as it can lead to unauthorized access and account creation. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.