CVE-2024-5150
CVE-2024-5150 allows attackers to bypass authentication in the 'Login with phone number' WordPress plugin. Unauthenticated users with access to a user's email can log in as any existing user, including administrators. The authentication bypass vulnerability affects versions up to 1.7.26. Although patched in 1.7.26, the patch introduced a new issue, resolved in version 1.7.27. While the CVSS score is 0, the SOCRadar Vulnerability Risk Score (SVRS) of 30 indicates a lower but existing level of risk, especially considering the 'In The Wild' tag. The potential for complete site compromise via administrator access makes prompt updating crucial. Despite the low SVRS score, consider upgrading to version 1.7.27 to eliminate the vulnerability and avoid potential exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.