Medium severity6.5NVD Advisory· Published Mar 14, 2022· Updated Jun 17, 2026
CVE-2022-0593
CVE-2022-0593
Description
The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service situation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:idehweb:login_with_phone_number:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:idehweb:login_with_phone_number:*:*:*:*:*:wordpress:*:*range: <1.3.7
- (no CPE)range: 1.3.7
- Range: <1.3.7
Patches
Vulnerability mechanics
References
2- wpscan.com/vulnerability/76a50157-04b5-43e8-afbc-a6ddf6d1cba3nvdExploitThird Party Advisory
- wordpress.org/plugins/login-with-phone-numbernvdThird Party Advisory
News mentions
0No linked articles in our index yet.