Extension WordPress

Vulnérabilités OTP Login With Phone Number, OTP Verification

Cette page rassemble les failles publiées pour OTP Login With Phone Number, OTP Verification, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
2Critiques
14Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de OTP Login With Phone Number, OTP Verification

14 fiches

CVE-2026-3655 Critique · 9,8
OTP Login With Phone Number, OTP Verification

OTP Login With Phone Number, OTP Verification <= 1.8.60 – Unauthenticated Authentication Bypass via Firebase OTP Verification

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase…

Versions affectées

1.8.50-1.8.60

Correctif

1.8.61

Publication

28/05/2026

CVE-2025-8342 Élevée · 8,1
OTP Login With Phone Number, OTP Verification

WooCommerce OTP Login With Phone Number, OTP Verification <= 1.8.47 – Authentication Bypass

The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value checking in the lwp_ajax_register function in all versions up to, and including, 1.8.47. This makes it…

Versions affectées

*-1.8.47

Correctif

1.8.48

Publication

14/08/2025

CVE-2024-6482 Élevée · 8,8
OTP Login With Phone Number, OTP Verification

Login with phone number <= 1.7.49 – Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation

The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the…

Versions affectées

*-1.7.49

Correctif

1.7.50

Publication

14/09/2024

CVE-2024-37429 Moyenne · 4,4
OTP Login With Phone Number, OTP Verification

Login with phone number <= 1.7.35 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Login with phone number plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

Versions affectées

*-1.7.35

Correctif

1.7.36

Publication

28/06/2024

CVE-2024-34371 Moyenne · 4,3
OTP Login With Phone Number, OTP Verification

Login with phone number <= 1.7.18 – Missing Authorization

The Login with phone number plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idehweb_lwp_update_billing_phones function in versions up to, and including, 1.7.18. This makes it possible for authenticated…

Versions affectées

*-1.7.18

Correctif

1.7.20

Publication

03/05/2024

CVE-2024-31424 Moyenne · 4,3
OTP Login With Phone Number, OTP Verification

Login with phone number <= 1.6.93 – Cross-Site Request Forgery

The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.93. This is due to missing or incorrect nonce validation on the lwp_forgot_password() and lwp_update_password_action() functions. This makes…

Versions affectées

*-1.6.93

Correctif

1.6.94

Publication

10/04/2024

CVE-2023-4916 Élevée · 8,8
OTP Login With Phone Number, OTP Verification

Login with phone number <= 1.5.6 – Cross-Site Request Forgery to User Password Change

The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function. This makes it possible for unauthenticated…

Versions affectées

*-1.5.6

Correctif

1.5.7

Publication

12/09/2023

CVE-2023-23492 Moyenne · 6,1
OTP Login With Phone Number, OTP Verification

Login with phone number <= 1.4.2 – Reflected Cross-Site Scripting

The Login with phone number plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.1 via the 'ID' parameter of the 'lwp_forgot_password' AJAX action. This makes it possible for unauthenticated attackers to…

Versions affectées

[*, 1.4.2)

Correctif

1.4.2

Publication

12/01/2023

CVE-2022-0593 Moyenne · 6,5
OTP Login With Phone Number, OTP Verification

Login with phone number <= 1.3.6 – Unauthenticated Remote Plugin Deletion

The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a…

Versions affectées

[*, 1.3.7)

Correctif

1.3.7

Publication

16/02/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités