CVE-2023-23492: SQL Injection
Published Jan 20, 2023
·Updated
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwpforgotpassword' action.
Affected Software
1 affected component
idehweb Login With Phone Number Wordpress<1.4.2
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-23492?
CVE-2023-23492 is considered a high-severity vulnerability due to its potential for authenticated SQL injection.
2
How do I fix CVE-2023-23492?
To fix CVE-2023-23492, update the Login with Phone Number WordPress Plugin to version 1.4.2 or later.
3
What impact does CVE-2023-23492 have on my website?
CVE-2023-23492 allows authenticated attackers to execute arbitrary SQL queries, potentially compromising your site's database.
4
Which versions of the Login with Phone Number plugin are affected by CVE-2023-23492?
CVE-2023-23492 affects all versions of the Login with Phone Number plugin prior to 1.4.2.
5
What action should I take if I cannot update the Login with Phone Number plugin due to compatibility issues?
If you cannot update the plugin, consider disabling it until a compatible version is available to mitigate risks from CVE-2023-23492.