Impact
An unauthenticated bypass flaw exists in the WordPress Login with phone number plugin versions 1.8.70 and older. The weakness allows a remote attacker to authenticate without valid credentials, and based on the description, it is inferred that this could enable full administrative rights to the affected WordPress site. This would expose the installation to confidentiality, integrity, and availability risks such as unauthorized content manipulation, plugin installation, or other system compromise.
Affected Systems
The plugin "Login with phone number" by Hamid Alinia is affected for all releases 1.8.70 and earlier. Any WordPress site that has deployed these versions is at risk unless the plugin is removed or upgraded to 1.8.71 or later.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity condition. Because the EPSS score is not provided, the historical exploitation probability is unclear, and the vulnerability is not listed in the CISA KEV catalog. The flaw is unauthenticated and involves a publicly reachable plugin endpoint, so an attacker only needs to send a crafted request to the login interface to potentially gain elevated privileges. No advanced prerequisites are described; the attack vector is broadly applicable to any site using the vulnerable plugin.
OpenCVE Enrichment