Description
Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.
Published: 2026-08-06
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated bypass flaw exists in the WordPress Login with phone number plugin versions 1.8.70 and older. The weakness allows a remote attacker to authenticate without valid credentials, and based on the description, it is inferred that this could enable full administrative rights to the affected WordPress site. This would expose the installation to confidentiality, integrity, and availability risks such as unauthorized content manipulation, plugin installation, or other system compromise.

Affected Systems

The plugin "Login with phone number" by Hamid Alinia is affected for all releases 1.8.70 and earlier. Any WordPress site that has deployed these versions is at risk unless the plugin is removed or upgraded to 1.8.71 or later.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity condition. Because the EPSS score is not provided, the historical exploitation probability is unclear, and the vulnerability is not listed in the CISA KEV catalog. The flaw is unauthenticated and involves a publicly reachable plugin endpoint, so an attacker only needs to send a crafted request to the login interface to potentially gain elevated privileges. No advanced prerequisites are described; the attack vector is broadly applicable to any site using the vulnerable plugin.

Generated by OpenCVE AI on August 6, 2026 at 16:13 UTC.

Remediation

Vendor Solution

Update the WordPress Login with phone number Plugin to the latest available version (at least 1.8.71).


OpenCVE Recommended Actions

  • Update the Login with phone number plugin to version 1.8.71 or later
  • If an immediate update is not feasible, temporarily disable or deactivate the plugin to block the attack surface
  • Perform an audit of WordPress administrator accounts to detect and remove any unauthorized users that may have been added during exploitation

Generated by OpenCVE AI on August 6, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.
Title WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vulnerability
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:40.850Z

Reserved: 2026-07-22T08:54:32.759Z

Link: CVE-2026-65570

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:15:12Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing