PT-2024-34664 · WordPress · Login With Phone Number

·

CVE-2024-5150

·

Published

2024-05-29

·

Updated

2024-05-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Login with phone number plugin for WordPress versions up to 1.7.26
Description The issue is related to authentication bypass due to the activation code default value being empty and a missing not empty check in the lwp ajax register function. This allows unauthenticated attackers to log in as any existing user, including administrators, if they have access to the user's email.
Recommendations For versions up to 1.7.26, update to version 1.7.27 to resolve the issue. As a temporary workaround, consider disabling the lwp ajax register function until the patch is applied.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5150

Affected Products

Login With Phone Number