Authentication vulnerability in Login with phone number 1.7.26

The Login with phone number plugin for WordPress has a security vulnerability in versions 1.7.26 and earlier. This allows hackers to bypass authentication and log in as any user on the site, including administrators, if they know the user’s email address. The vulnerability has been fixed in version 1.7.26, but there was a problem with the patch that prevented the function from working. This was resolved in version 1.7.27.

Detected in:

Login with phone number open vulnerable versions: >= * <= 1.7.26

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.