OTP Login With Phone Number, OTP Verification <= 1.8.70 - OTP Brute Force
critical
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to OTP Brute Force in all versions up to, and including, 1.8.70. This makes it possible for unauthenticated attackers to brute force and bypass OTP verification.
- CVSS:
- 9.8
- Affected:
- up to 1.8.70
- Fixed in:
- 1.8.71
- Disclosed:
- Aug 6, 2026
CVE-2026-65570 on NVD →
OTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Authentication Bypass via Firebase OTP Verification
critical
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The `idehwe...
- CVSS:
- 9.8
- Affected:
- 1.8.50 – 1.8.60
- Fixed in:
- 1.8.61
- Disclosed:
- May 28, 2026
CVE-2026-3655 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification <= 1.8.47 - Authentication Bypass
high
The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value checking in the lwp_ajax_register function in all versions up to, and including, 1.8.47. This makes it possible for unauthenticated attackers to bypass OTP verificati...
- CVSS:
- 8.1
- Affected:
- up to 1.8.47
- Fixed in:
- 1.8.48
- Disclosed:
- Aug 14, 2025
CVE-2025-8342 on NVD →
Login with phone number <= 1.7.49 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation
high
The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the 'lwp_update_password_action' function. This makes it possible for authenticated attackers, wi...
- CVSS:
- 8.8
- Affected:
- up to 1.7.49
- Fixed in:
- 1.7.50
- Disclosed:
- Sep 14, 2024
CVE-2024-6482 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.7.50
unknown
[en] The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the 'lwp_update_password_action' function. This makes it possible for authenticated attacker...
- Affected:
- up to 1.7.50
- Fixed in:
- 1.7.50
- Disclosed:
- Sep 14, 2024
CVE-2024-6482 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.7.36
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hamid Alinia – idehweb Login with phone number allows Stored XSS.This issue affects Login with phone number: from n/a through 1.7.35.
- Affected:
- up to 1.7.36
- Fixed in:
- 1.7.36
- Disclosed:
- Jul 22, 2024
CVE-2024-37429 on NVD →
Login with phone number <= 1.7.35 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Login with phone number plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web script...
- CVSS:
- 4.4
- Affected:
- up to 1.7.35
- Fixed in:
- 1.7.36
- Disclosed:
- Jun 28, 2024
CVE-2024-37429 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.7.35
unknown
[en] The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.7.34. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit. This makes it possible for unauthenticated attack...
- Affected:
- up to 1.7.35
- Fixed in:
- 1.7.35
- Disclosed:
- Jun 19, 2024
CVE-2024-6125 on NVD →
Login with phone number <= 1.7.34 - Insecure Password Reset Mechanism
high
The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.7.34. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit. This makes it possible for unauthenticated attackers t...
- CVSS:
- 8.1
- Affected:
- up to 1.7.34
- Fixed in:
- 1.7.35
- Disclosed:
- Jun 18, 2024
CVE-2024-6125 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.7.27
unknown
[en] The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.26. This is due to the 'activation_code' default value is empty, and the not empty check is missing in the 'lwp_ajax_register' function. This makes it possible for unauthenticated attackers...
- Affected:
- up to 1.7.27
- Fixed in:
- 1.7.27
- Disclosed:
- May 29, 2024
CVE-2024-5150 on NVD →
Login with phone number <= 1.7.26 - Authentication Bypass due to Missing Empty Value Check
critical
The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.26. This is due to the 'activation_code' default value is empty, and the not empty check is missing in the 'lwp_ajax_register' function. This makes it possible for unauthenticated attackers to l...
- CVSS:
- 9.8
- Affected:
- up to 1.7.26
- Fixed in:
- 1.7.27
- Disclosed:
- May 28, 2024
CVE-2024-5150 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.7.17
unknown
[en] Improper Privilege Management vulnerability in Hamid Alinia – idehweb Login with phone number allows Privilege Escalation.This issue affects Login with phone number: from n/a through 1.7.16.
- Affected:
- up to 1.7.17
- Fixed in:
- 1.7.17
- Disclosed:
- May 17, 2024
CVE-2024-32507 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.7.20
unknown
[en] Missing Authorization vulnerability in Hamid Alinia – idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.7.18.
- Affected:
- up to 1.7.20
- Fixed in:
- 1.7.20
- Disclosed:
- May 6, 2024
CVE-2024-34371 on NVD →
Login with phone number <= 1.7.18 - Missing Authorization
medium
The Login with phone number plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idehweb_lwp_update_billing_phones function in versions up to, and including, 1.7.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to...
- CVSS:
- 4.3
- Affected:
- up to 1.7.18
- Fixed in:
- 1.7.20
- Disclosed:
- May 3, 2024
CVE-2024-34371 on NVD →
Login with phone number <= 1.6.93 - Missing Authorization
medium
The Login with phone number plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a function in versions up to, and including, 1.6.93. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.6.93
- Fixed in:
- 1.6.94
- Disclosed:
- Apr 22, 2024
CVE-2024-32832 on NVD →
Login with phone number <= 1.7.16 - Unauthorized Account Password Change to Privilege Escalation
high
The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.16. This is due to the plugin not properly verifying the identity of a user who is trying to reset a password. This makes it possible for authenticated attackers, with subscriber-level access...
- CVSS:
- 8.8
- Affected:
- up to 1.7.16
- Fixed in:
- 1.7.17
- Disclosed:
- Apr 15, 2024
CVE-2024-32507 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.6.94
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia - idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.6.93.
- Affected:
- up to 1.6.94
- Fixed in:
- 1.6.94
- Disclosed:
- Apr 15, 2024
CVE-2024-31424 on NVD →
Login with phone number <= 1.6.93 - Cross-Site Request Forgery
medium
The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.93. This is due to missing or incorrect nonce validation on the lwp_forgot_password() and lwp_update_password_action() functions. This makes it possible for unauthenticated attackers to upd...
- CVSS:
- 4.3
- Affected:
- up to 1.6.93
- Fixed in:
- 1.6.94
- Disclosed:
- Apr 10, 2024
CVE-2024-31424 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.5.7
unknown
[en] The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function. This makes it possible for unauthenticated attackers to change user password via a forged reque...
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.7
- Disclosed:
- Sep 13, 2023
CVE-2023-4916 on NVD →
Login with phone number <= 1.5.6 - Cross-Site Request Forgery to User Password Change
high
The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function. This makes it possible for unauthenticated attackers to change user password via a forged request gr...
- CVSS:
- 8.8
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.7
- Disclosed:
- Sep 12, 2023
CVE-2023-4916 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.4.2
unknown
[en] The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
- Disclosed:
- Jan 20, 2023
CVE-2023-23492 on NVD →
Login with phone number <= 1.4.2 - Reflected Cross-Site Scripting
medium
The Login with phone number plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.1 via the 'ID' parameter of the 'lwp_forgot_password' AJAX action. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
- Disclosed:
- Jan 12, 2023
CVE-2023-23492 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.3.8
unknown
[en] The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.8
- Disclosed:
- Aug 1, 2022
CVE-2022-0598 on NVD →
Login with phone number <= 1.3.7 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Login with phone number WordPress plugin through 1.3.7 do not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.8
- Disclosed:
- Jul 5, 2022
CVE-2022-0598 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.3.7
unknown
[en] The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service situation.
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- Mar 14, 2022
CVE-2022-0593 on NVD →
Login with phone number <= 1.3.6 - Unauthenticated Remote Plugin Deletion
medium
The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service situation.
- CVSS:
- 6.5
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- Feb 16, 2022
CVE-2022-0593 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.6.94
unknown
- Affected:
- up to 1.6.94
- Fixed in:
- 1.6.94
CVE-2024-32832 on NVD →
WooCommerce OTP Login With Phone Number, OTP Verification [login-with-phone-number] < 1.8.48
unknown
- Affected:
- up to 1.8.48
- Fixed in:
- 1.8.48
CVE-2025-8342 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database