Extension WordPress
Vulnérabilités OTP Login With Phone Number, OTP Verification
Cette page rassemble les failles publiées pour OTP Login With Phone Number, OTP Verification, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de OTP Login With Phone Number, OTP Verification
14 fiches
OTP Login With Phone Number, OTP Verification <= 1.8.60 – Unauthenticated Authentication Bypass via Firebase OTP Verification
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase…
1.8.50-1.8.60
1.8.61
28/05/2026
WooCommerce OTP Login With Phone Number, OTP Verification <= 1.8.47 – Authentication Bypass
The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value checking in the lwp_ajax_register function in all versions up to, and including, 1.8.47. This makes it…
*-1.8.47
1.8.48
14/08/2025
Login with phone number <= 1.7.49 – Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation
The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the…
*-1.7.49
1.7.50
14/09/2024
Login with phone number <= 1.7.35 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Login with phone number plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
*-1.7.35
1.7.36
28/06/2024
Login with phone number <= 1.7.34 – Insecure Password Reset Mechanism
The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.7.34. This is due to the plugin generating too weak a reset code, and the code used to…
*-1.7.34
1.7.35
18/06/2024
Login with phone number <= 1.7.26 – Authentication Bypass due to Missing Empty Value Check
The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.26. This is due to the 'activation_code' default value is empty, and the not empty check is missing in…
*-1.7.26
1.7.27
28/05/2024
Login with phone number <= 1.7.18 – Missing Authorization
The Login with phone number plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idehweb_lwp_update_billing_phones function in versions up to, and including, 1.7.18. This makes it possible for authenticated…
*-1.7.18
1.7.20
03/05/2024
Login with phone number <= 1.6.93 – Missing Authorization
The Login with phone number plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a function in versions up to, and including, 1.6.93. This makes it possible for unauthenticated attackers…
*-1.6.93
1.6.94
22/04/2024
Login with phone number <= 1.7.16 – Unauthorized Account Password Change to Privilege Escalation
The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.16. This is due to the plugin not properly verifying the identity of a user who is trying…
*-1.7.16
1.7.17
15/04/2024
Login with phone number <= 1.6.93 – Cross-Site Request Forgery
The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.93. This is due to missing or incorrect nonce validation on the lwp_forgot_password() and lwp_update_password_action() functions. This makes…
*-1.6.93
1.6.94
10/04/2024
Login with phone number <= 1.5.6 – Cross-Site Request Forgery to User Password Change
The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function. This makes it possible for unauthenticated…
*-1.5.6
1.5.7
12/09/2023
Login with phone number <= 1.4.2 – Reflected Cross-Site Scripting
The Login with phone number plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.1 via the 'ID' parameter of the 'lwp_forgot_password' AJAX action. This makes it possible for unauthenticated attackers to…
[*, 1.4.2)
1.4.2
12/01/2023
Login with phone number <= 1.3.7 – Authenticated (Admin+) Stored Cross-Site Scripting
The Login with phone number WordPress plugin through 1.3.7 do not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
*-1.3.7
1.3.8
05/07/2022
Login with phone number <= 1.3.6 – Unauthenticated Remote Plugin Deletion
The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a…
[*, 1.3.7)
1.3.7
16/02/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.