CVE-2023-23492

high

Description

The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.

References

https://www.tenable.com/security/research/tra-2023-3

Details

Source: MITRE

Published: 2023-01-20

Updated: 2023-01-27

Type: CWE-89