idehweb records
7 published records for vendor idehweb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 42.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-269 Improper Privilege Management1
- CWE-73 External Control of File Name or Path1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2023-23492Proof of concept | The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' paramidehweb · login with phone number · CWE-89 | High8.8 | — | 57.1% | Jan 20, 2023 |
35Monitor | CVE-2024-6482No exploit | Login with phone number <= 1.7.49 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalationidehweb · login with phone number · CWE-269 | High8.8 | — | 0.5% | Sep 14, 2024 |
35Monitor | CVE-2023-4916No exploit | Login with phone number <= 1.5.6 - Cross-Site Request Forgery to User Password Changeidehweb · login with phone number · CWE-352 | High8.8 | — | 0.4% | Sep 12, 2023 |
35Monitor | CVE-2024-31424No exploit | WordPress Login with Phone Number plugin <= 1.6.93 - Cross Site Request Forgery (CSRF) vulnerabilityhamid alinia · login with phone number · CWE-352 | High8.8 | — | 0.3% | Apr 15, 2024 |
26Monitor | CVE-2022-0593No exploit | Login with phone number < 1.3.7 - Unauthenticated remote plugin deletionidehweb · login with phone number · CWE-73 | Medium6.5 | — | 1.4% | Mar 14, 2022 |
19Monitor | CVE-2022-0598No exploit | Login with phone number < 1.3.8 - Multiple Admin+ Stored XSSidehweb · login with phone number · CWE-79 | Medium4.8 | — | 0.7% | Aug 1, 2022 |
19Monitor | CVE-2024-37429No exploit | WordPress Login with phone number plugin <= 1.7.35 - Admin+ Cross Site Scripting (XSS) vulnerabilityidehweb · login with phone number · CWE-79 | Medium4.8 | — | 0.3% | Jul 22, 2024 |
- CVE-2023-2349252Plan
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' param
HighCVSS 8.8Proof of conceptEPSS 57%idehweb · login with phone numberJan 20, 2023
- CVE-2024-648235Monitor
Login with phone number <= 1.7.49 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation
HighCVSS 8.8No exploitEPSS 0%idehweb · login with phone numberSep 14, 2024
- CVE-2023-491635Monitor
Login with phone number <= 1.5.6 - Cross-Site Request Forgery to User Password Change
HighCVSS 8.8No exploitEPSS 0%idehweb · login with phone numberSep 12, 2023
- CVE-2024-3142435Monitor
WordPress Login with Phone Number plugin <= 1.6.93 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%hamid alinia · login with phone numberApr 15, 2024
- CVE-2022-059326Monitor
Login with phone number < 1.3.7 - Unauthenticated remote plugin deletion
MediumCVSS 6.5No exploitEPSS 1%idehweb · login with phone numberMar 14, 2022
- CVE-2022-059819Monitor
Login with phone number < 1.3.8 - Multiple Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 1%idehweb · login with phone numberAug 1, 2022
- CVE-2024-3742919Monitor
WordPress Login with phone number plugin <= 1.7.35 - Admin+ Cross Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%idehweb · login with phone numberJul 22, 2024