cleantalk
Vulnerabilities and Security Researches

Login with phone number, CVE-2022-0598

CVE, Research URL

CVE-2022-0598

Published on
Aug 01, 2022
Research Description
The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected versions
max 1.3.8.
Status
vulnerable