Record summary

CVE-2023-23492 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Login with Phone Number WordPress Plugin

CVE List< 1.4.2affected

Nuclei templates

1
ProjectDiscoveryHIGHLogin with Phone Number - Cross-Site ScriptingCVSS 8.8

Login with Phone Number, versions < 1.4.2, is affected by an reflected XSS vulnerability in the login-with-phonenumber.php' file in the 'lwp_forgot_password()' function.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the application, leading to the theft of sensitive user information or unauthorized actions.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-89
Authorsr3Y3r53
Template tagscve2023cvelogin-with-phonenumberwordpresswpwp-pluginxsstenableidehwebvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:idehweb:login_with_phone_number:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2