Login with phone number <= 1.7.16 - Unauthorized Account Password Change to Privilege Escalation

2024-04-15 00:00
Emili Castells

Strategic Overview

Status
Patched in 1.7.17
Affected Version<= 1.7.16
CVSS8.8High
CVECVE-2024-32507
View all OTP Login With Phone Number, OTP Verification vulnerabilities

Vulnerability Overview

The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.16. This is due to the plugin not properly verifying the identity of a user who is trying to reset a password. This makes it possible for authenticated attackers, with subscriber-level access and above, to gain access to administrative user accounts.

Technical Analysis

REMEDIATION: Update to version 1.7.17, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C