CVE-2026-65570 HIGH

CVE-2026-65570: WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vulnerability

Vendor Hamid Alinia
Product Login with phone number
Weakness CWE-290
Published August 6, 2026
Last update August 6, 2026

CVSS base score

8.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Login with Phone Number versions up to 1.8.70 contain an authentication bypass vulnerability. An attacker can spoof phone number verification to gain unauthorized access without valid credentials. The vulnerability requires specific network conditions but no user interaction. All confidentiality, integrity, and availability protections are compromised.

What an attacker can do

03Attacker Capabilities

Bypass phone number authentication and gain unauthorized access to user accounts.

Potential impact on your site

04Site Impact

Attackers can access any user account, including admin accounts, without knowing passwords.

Conditions required to exploit

05Prerequisites

Network access to the application; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated