S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-23492 Scanner

CVE-2023-23492 scanner - SQL Injection (SQLi) vulnerability in Login with Phone Number plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-23492
8.8
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Login with Phone Number WordPress Pluginby n/a
< 1.4.2
Updated Aug 22, 2026View on NVD →
Detail

The Login with Phone Number plugin for WordPress is an authentication solution that enables users to register, log in, or recover their account credentials by using their phone number. This plugin is widely used by website owners and administrators who want to streamline the authentication process for their users. The plugin comes with various features such as one-click registration, SMS notifications, and two-factor authentication to enhance the security of the user's account.

However, this plugin has been found to have a severe vulnerability, detected as CVE-2023-23492. This vulnerability is an authenticated SQL injection in the 'ID' parameter of the 'lwp_forgot_password' action. An attacker who has a valid user account could exploit this vulnerability to execute arbitrary SQL code, which could lead to unauthorized access to sensitive information or the entire website's database. The attacker could also utilize this vulnerability to escalate their privileges, execute arbitrary malicious code, and gain complete control over the WordPress website.

When successfully exploited, this vulnerability could lead to severe consequences, including but not limited to website defacement, data theft, or financial losses due to exposure of critical data. Cybercriminals have been known to exploit SQL injection vulnerabilities to inject malicious code into the database, which, in turn, could lead to client-side attacks or malware installation through malicious code injection.

In conclusion, the Login with Phone Number plugin for WordPress is a useful tool that can streamline the authentication process for website users; however, it is not immune to vulnerabilities. It is crucial to keep the plugin regularly updated and apply the necessary precautions to prevent potential exploits. Thanks to s4e.io, users can easily and quickly learn about vulnerabilities in their digital assets by utilizing the platform's advanced features and capabilities.

 

REFERENCES

Solution Advice

To mitigate the risk associated with this vulnerability, website owners and administrators can take the following precautions:

  • Update the plugin to the latest version, which contains the patch for the vulnerability.
  • If the website uses the affected version of the plugin, disable it until the update is installed.
  • Regularly monitor the website logs to detect any suspicious activities that could indicate an ongoing attack.
  • Educate website users on the importance of strong passwords and two-factor authentication to prevent unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.