What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93.
Explanation of Vulnerability in Simple Terms
The Login with Phone Number plugin for WordPress contains a cross-site request forgery (CSRF) vulnerability affecting versions up to 1.6.93. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unauthorized actions on the site without the admin's knowledge or consent. This could allow account takeover, data modification, or other administrative changes.
What an attacker can do
Perform unauthorized actions on the site by tricking an admin into visiting a malicious webpage.
Potential impact on your site
Admins could unknowingly authorize account changes, plugin modifications, or data deletion via a malicious link.
Conditions required to exploit
A site administrator must visit a page controlled by the attacker while logged into WordPress.
Key dates
External resources
Related vulnerabilities