CVE-2024-32832
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-31

Last updated on: 2026-04-23

Assigner: Patchstack

Description
Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-31
Last Modified
2026-04-23
Generated
2026-06-16
AI Q&A
2025-08-31
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack login_with_phone_number *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a Missing Authorization (Broken Access Control) flaw in the WordPress plugin "Login with Phone Number" up to version 1.6.93. It allows unauthenticated users to perform actions that should be restricted to higher-privileged users because the plugin lacks proper authorization, authentication, or nonce token checks. This means attackers can bypass security controls and potentially take over or manipulate the site. [1]

Impact Analysis

The vulnerability has a critical impact with a CVSS score of 9.8. It can allow attackers to gain unauthorized access and perform high-impact actions such as compromising confidentiality, integrity, and availability of the affected system. This can lead to site takeover, data breaches, and service disruption. The vulnerability is actively exploited in the wild and expected to see mass exploitation, making it urgent to update the plugin to version 1.6.94 or later. [1]

Detection Guidance

The provided resources do not include specific commands or detailed methods to detect this vulnerability on your network or system. Detection would likely involve monitoring for unauthorized access attempts or checking the plugin version installed, but no explicit detection commands are given.

Mitigation Strategies

Immediate mitigation steps include updating the WordPress plugin "Login with Phone Number" to version 1.6.94 or later, which contains the fix for this vulnerability. Alternatively, applying the Patchstack virtual patch (vPatch) can automatically block attacks until the update is performed. It is also recommended to perform professional incident response and server-side malware scanning if compromise is suspected. [1]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-32832. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart