Vulnerability record · CVE-2023-23492 · published 20 January 2023
CVE-2023-23492: Login with Phone Number WordPress plugin authenticated SQL injection
Idehweb · Login With Phone Number
The Login with Phone Number WordPress plugin before version 1.4.2 is affected by an authenticated SQL injection in the 'ID' parameter of its 'lwp_forgot_password' action. An attacker with a low-privileged account can inject SQL through that parameter, which matters because the plugin is widely deployed on WordPress sites and the flaw exposes the database.
Description
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high confidentiality, integrity and availability impact, public exploit references, and a very high EPSS score, though exploitation requires an authenticated account.
What it is
The Login with Phone Number WordPress plugin before version 1.4.2 is affected by an authenticated SQL injection in the 'ID' parameter of its 'lwp_forgot_password' action. An attacker with a low-privileged account can inject SQL through that parameter, which matters because the plugin is widely deployed on WordPress sites and the flaw exposes the database.
Impact
An attacker gains read and write access to the underlying database, enabling theft of user credentials and other stored data, and potentially full compromise of the WordPress site.
Attack surface
Reachable over the network through the plugin's 'lwp_forgot_password' action, requiring a low-privileged authenticated account and no user interaction.
Exploitation
Not listed in CISA KEV, but EPSS is 0.57123 (99th percentile) and the only references are tagged Exploit, indicating public exploit code exists.
What to do
- Update the Login with Phone Number plugin to version 1.4.2 or later.
- If patching is not immediately possible, disable or remove the plugin until it can be updated.
- Restrict and audit low-privileged accounts, since exploitation requires authentication.
- Deploy a web application firewall rule to block SQL injection attempts against the lwp_forgot_password action.
Detection
- Monitor web server and plugin logs for requests to the lwp_forgot_password action containing SQL syntax in the ID parameter.
- Alert on database errors or unusual query patterns originating from WordPress plugin endpoints.
- Review low-privileged account activity for abnormal database access or data exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tenable.com/security/research/tra-2023-3 | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2023-3 | ExploitThird Party Advisory |
Track CVE-2023-23492 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-23492), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.