WordPress Login with phone number plugin <= 1.7.16 - Privilege Escalation vulnerability
43Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 8.8epss 0.5%
from disclosure to weapon
Published on NVDMay 17
VulnCheckApr 15
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
yesVulnCheck
Incorrect Privilege Assignment vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.16.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Hamid Alinia · Login with phone numberReferences
https://patchstack.com/database/vulnerability/login-with-phone-number/wordpress-login-with-phone-number-plugin-1-7-16-privilege-escalation-vulnerability?_s_id=cvehttps://patchstack.com/database/Wordpress/Plugin/login-with-phone-number/vulnerability/wordpress-login-with-phone-number-plugin-1-7-16-privilege-escalation-vulnerability?_s_id=cve