Idehweb's vulnerability footprint concentrates in a narrowly scoped authentication product, Login with Phone Number, where disclosures cluster around web-application input-handling and access-control weaknesses including cross-site scripting, CSRF, SQL injection, and improper privilege management. The vendor's exposure has an elevated tendency toward public exploit availability, making timely patch deployment important for installations relying on this authentication component. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Idehweb over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23492HIGH The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action | Jan 20, 2023 | 8.8 | 70 | NO | YES |
CVE-2024-6482HIGH The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing | Sep 14, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-4916HIGH The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the | Sep 13, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-0598MEDIUM The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attack | Aug 1, 2022 | 4.8 | 19 | NO | NO |
CVE-2022-0593MEDIUM The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing | Mar 14, 2022 | 6.5 | 18 | NO | NO |
CVE-2024-37429MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affect | Jul 22, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Idehweb.
Media articles that mention a CVE ID that affects a product developed by Idehweb — matched by CVE ID, not by vendor name.