CVE-2022-0593: Idehweb Login With Phone Number
Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.
The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service situation.
Affected products
- Idehweb Login With Phone Number: before 1.3.7 (fixed in 1.3.7)
Published 2022-03-14. Last modified 2026-06-17.