Idehweb

Login With Phone Number

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Veröffentlicht 14.09.2024 13:15:10
  • Zuletzt bearbeitet 27.09.2024 13:54:53

The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the 'lwp_update_password_ac...

  • EPSS 0.11%
  • Veröffentlicht 22.07.2024 09:15:09
  • Zuletzt bearbeitet 21.11.2024 09:23:50

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hamid Alinia – idehweb Login with phone number allows Stored XSS.This issue affects Login with phone number: from n/a through 1.7.35.

  • EPSS 0.57%
  • Veröffentlicht 17.05.2024 09:15:36
  • Zuletzt bearbeitet 21.11.2024 09:15:03

Improper Privilege Management vulnerability in Hamid Alinia – idehweb Login with phone number allows Privilege Escalation.This issue affects Login with phone number: from n/a through 1.7.16.

  • EPSS 0.15%
  • Veröffentlicht 06.05.2024 19:15:07
  • Zuletzt bearbeitet 21.11.2024 09:18:31

Missing Authorization vulnerability in Hamid Alinia – idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.7.18.

  • EPSS 0.36%
  • Veröffentlicht 15.04.2024 10:15:09
  • Zuletzt bearbeitet 21.11.2024 09:13:30

Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia - idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.6.93.

  • EPSS 0.13%
  • Veröffentlicht 13.09.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 08:36:15

The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function. This makes it possible for una...

Exploit
  • EPSS 86.22%
  • Veröffentlicht 20.01.2023 19:15:18
  • Zuletzt bearbeitet 03.04.2025 20:15:22

The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.

Exploit
  • EPSS 0.44%
  • Veröffentlicht 01.08.2022 13:15:09
  • Zuletzt bearbeitet 21.11.2024 06:38:59

The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 14.03.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 06:38:59

The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a...