CVE-2023-23492: Idehweb Login With Phone Number

High severity, CVSS 8.8. EPSS: 57.1% chance of exploitation in the next 30 days.

The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.

Affected products

  • Idehweb Login With Phone Number: before 1.4.2 (fixed in 1.4.2)

Published 2023-01-20. Last modified 2026-06-17.