Idehweb
Idehweb Login With Phone Number: vulnerabilidades y CVE
Idehweb Login With Phone Number tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-32832 | Crítica (9.8) | 0.36% | — | 31 ago 2025 | Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93. |
| CVE-2024-6482 | Alta (8.8) | 0.48% | — | 14 sept 2024 | The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data… |
| CVE-2024-37429 | Media (4.8) | 0.26% | — | 22 jul 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a… |
| CVE-2024-6125 | Alta (8.1) | 0.46% | — | 19 jun 2024 | The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.7.34. This is due to the plugin generating too weak a reset code, and the code used to… |
| CVE-2024-5150 | Crítica (9.8) | 0.80% | — | 29 may 2024 | The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.26. This is due to the 'activation_code' default value is empty, and the not empty check is… |
| CVE-2024-32507 | Alta (8.8) | 0.46% | — | 17 may 2024 | Incorrect Privilege Assignment vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.16. |
| CVE-2024-34371 | Media (4.3) | 0.39% | — | 6 may 2024 | Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.18. |
| CVE-2024-31424 | Alta (8.8) | 0.31% | — | 15 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93. |
| CVE-2023-4916 | Alta (8.8) | 0.41% | — | 13 sept 2023 | The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function.… |
| CVE-2023-23492 | Alta (8.8) | 57% | — | 20 ene 2023 | The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action. |
| CVE-2022-0598 | Media (4.8) | 0.69% | — | 1 ago 2022 | The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html… |
| CVE-2022-0593 | Media (6.5) | 1.4% | — | 14 mar 2022 | The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.