CVE-2022-0598 Information
Aug 02, 2022
cve
Description
The Login with phone number WordPress plugin through 1.3.7 do not sanitise and escape plugin settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Reference
https://wpscan.com/vulnerability/4688d39e-ac9b-47f5-a4c1-f9548b63c68c
Share on: