CVE-2022-0593: Login with phone number < 1.3.7 - Unauthenticated remote plugin deletion
The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service situation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0593?
CVE-2022-0593 has a high severity rating due to its potential to allow unauthorized file deletion.
How do I fix CVE-2022-0593?
To fix CVE-2022-0593, you should update the Login with Phone Number plugin to version 1.3.7 or later.
Who is affected by CVE-2022-0593?
CVE-2022-0593 affects users of the Login with Phone Number WordPress plugin versions prior to 1.3.7.
What can an attacker do with CVE-2022-0593?
An attacker can exploit CVE-2022-0593 to remotely delete plugin files, potentially causing a Denial of Service.
Is authentication required to exploit CVE-2022-0593?
No, CVE-2022-0593 can be exploited by unauthenticated users, which increases its risk.