CVE-2023-4916: Login with phone number <= 1.5.6 - Cross-Site Request Forgery to User Password Change
The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwpupdatepasswordaction' function. This makes it possible for unauthenticated attackers to change user password via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4916?
CVE-2023-4916 has a high severity rating due to its potential for unauthorized password changes by unauthenticated attackers.
How do I fix CVE-2023-4916?
To fix CVE-2023-4916, update the Login with Phone Number plugin to version 1.5.7 or later, which includes nonce validation enhancements.
Which versions of the Login with Phone Number plugin are affected by CVE-2023-4916?
CVE-2023-4916 affects all versions of the Login with Phone Number plugin up to and including 1.5.6.
What kind of attack can exploit CVE-2023-4916?
CVE-2023-4916 can be exploited through Cross-Site Request Forgery, allowing attackers to change user passwords.
Is CVE-2023-4916 exploitable without authentication?
Yes, CVE-2023-4916 is exploitable by unauthenticated attackers, making it a critical vulnerability.