Cross-Site Request Forgery Vulnerability in Login with Phone Number Plugin by WordPress
CVE-2023-4916
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 September 2023
What is CVE-2023-4916?
The Login with Phone Number plugin for WordPress is prone to a Cross-Site Request Forgery vulnerability due to inadequate nonce validation in the 'lwp_update_password_action' function. This flaw allows unauthenticated adversaries to potentially alter user passwords through a forged request, requiring only that the attacker deceives an admin into clicking a malicious link, thus exposing user credentials to unauthorized access.
Affected Version(s)
OTP Login With Phone Number, OTP Verification 0 <= 1.5.6