CVE-2026-65570

Hamid Alinia · Login with phone number

The Login with phone number WordPress plugin contains an authentication bypass vulnerability, allowing unauthenticated attackers to spoof identity and gain unauthorized access.

Executive summary

An authentication bypass vulnerability in the Login with phone number WordPress plugin allows unauthenticated attackers to gain unauthorized access to the system.

Vulnerability

This is an authentication bypass vulnerability (CWE-290) resulting from improper validation of authentication credentials. It allows an unauthenticated attacker to successfully authenticate by spoofing the login process.

Business impact

The vulnerability carries a CVSS score of 8.1, reflecting its potential for full account takeover. By bypassing the login mechanism, attackers can gain unauthorized access to user accounts, including administrative accounts, leading to total compromise of the affected WordPress site and its data.

Remediation

Immediate Action: Update the Login with phone number plugin to version 1.8.71 or higher immediately.

Proactive Monitoring: Audit WordPress user account logs for suspicious account creations, privilege escalations, or unauthorized logins occurring during the period the vulnerable plugin was active.

Compensating Controls: If immediate patching is not possible, deactivate the plugin and utilize alternative authentication methods until the update can be verified and applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This is a critical security update for any WordPress environment using the Login with phone number plugin. Administrators must apply the update to version 1.8.71 immediately to close this authentication bypass vector and prevent potential account takeovers.