Authentication vulnerability in Login with phone number 1.7.34

The Login with phone number plugin for WordPress has a security vulnerability that allows unauthorized users to reset passwords without permission. This can happen in versions 1.7.34 and below. The problem is caused by the plugin creating a weak reset code and not having any limits on how many times the code can be used. This means that anyone without proper access can potentially change the password of any user by guessing a simple 6-digit code.

Detected in:

Login with phone number open vulnerable versions: >= * <= 1.7.34

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.