Critical Vulnerability in OTP Login With Phone Number, OTP Verification WordPress Plugin
A critical vulnerability (CVE-2026-15210, CVSS 9.1) exists in the OTP Login With Phone Number, OTP Verification WordPress plugin prior to version 1.8.71. An unauthenticated attacker can brute-force OTP login codes to gain account control, including administrator accounts. Immediate action is required to update the plugin.