PT-2024-37658 · WordPress · Login With Phone Number
Thanh Nam Tran
·
Published
2024-09-14
·
Updated
2024-09-27
·
CVE-2024-6482
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Login with phone number plugin for WordPress versions up to, and including, 1.7.49
Description
The issue is due to a lack of validation and missing capability check on user-supplied data in the
lwp update password action function. This allows authenticated attackers, with Subscriber-level access and above, to update their role to any other role, including Administrator. The vulnerability was partially patched in version 1.7.40, but the login with phone number pro plugin was required to exploit the vulnerability in versions 1.7.40 - 1.7.49.Recommendations
For versions up to 1.7.39, update to a version above 1.7.49 to fully resolve the issue.
For versions 1.7.40 - 1.7.49, ensure the login with phone number pro plugin is not installed or used, and update to a version above 1.7.49 to fully resolve the issue.
As a temporary workaround, consider disabling the
lwp update password action function until a patch is available.Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Login With Phone Number