CVE-2023-23492
Login with Phone Number - Cross-Site Scripting
Record summary
CVE-2023-23492 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Login with Phone Number WordPress Plugin | CVE List | < 1.4.2 | affected |
Nuclei templates
1ProjectDiscoveryHIGHLogin with Phone Number - Cross-Site ScriptingCVSS 8.8
Login with Phone Number, versions < 1.4.2, is affected by an reflected XSS vulnerability in the login-with-phonenumber.php' file in the 'lwp_forgot_password()' function.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the application, leading to the theft of sensitive user information or unauthorized actions.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery