CVE-2022-0598: Login with phone number < 1.3.8 - Multiple Admin+ Stored XSS
The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0598?
CVE-2022-0598 is rated as a high severity vulnerability due to its potential to allow Cross-Site Scripting attacks.
How do I fix CVE-2022-0598?
To fix CVE-2022-0598, update the Login with Phone Number WordPress plugin to version 1.3.8 or later.
Who is affected by CVE-2022-0598?
CVE-2022-0598 affects users of the Login with Phone Number WordPress plugin versions prior to 1.3.8.
What type of attack can CVE-2022-0598 facilitate?
CVE-2022-0598 can facilitate Cross-Site Scripting (XSS) attacks due to inadequate sanitization and escaping of plugin settings.
What are the consequences of exploiting CVE-2022-0598?
Exploiting CVE-2022-0598 can allow attackers to execute malicious scripts in the context of a user's browser, potentially leading to data theft or site compromise.