Vulnerabilities > CVE-2022-0593 - Unspecified vulnerability in Idehweb Login With Phone Number

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
LOW
network
low complexity
idehweb

Summary

The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service situation.

Vulnerable Configurations

Part Description Count
Application
Idehweb
55