← Back to browse · API

CVE-2023-23492

Severity
HIGH
CVSS
8.8
EPSS
0.57123
Risk score
55.19
CISA KEV
No
PoC
No
Published
2023-01-20
Modified
2025-04-03
First seen
2026-08-07
Aliases
EUVD-2023-27592, GHSA-QG8J-VJ2P-Q63J
Products
n/a:Login with Phone Number WordPress Plugin < 1.4.2
Sources
euvd EUVD-2023-27592

Description

The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.

References