VendorsIdehweblogin_with_phone_numberany version
Vulnerabilities

Idehweb Login With Phone Number any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-23492
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.
Published 2023-01-20 · Modified
8.8EPSS 0.571
CVE-2024-6482
Login with phone number <= 1.7.49 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation
Published 2024-09-14 · Analyzed
8.8EPSS 0.005
CVE-2023-4916
Login with phone number <= 1.5.6 - Cross-Site Request Forgery to User Password Change
Published 2023-09-13 · Modified
8.8EPSS 0.004
CVE-2022-0593
Login with phone number < 1.3.7 - Unauthenticated remote plugin deletion
Published 2022-03-14 · Modified
6.5EPSS 0.014
CVE-2024-37429
WordPress Login with phone number plugin <= 1.7.35 - Admin+ Cross Site Scripting (XSS) vulnerability
Published 2024-07-22 · Modified
5.9EPSS 0.003
CVE-2022-0598
Login with phone number < 1.3.8 - Multiple Admin+ Stored XSS
Published 2022-08-01 · Modified
4.8EPSS 0.007