Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-32832 — AI Deep Analysis Summary

CVSS 9.8 · Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: Broken Access Control in 'Login with phone number' plugin. 📉 **Consequences**: Attackers bypass authentication, gaining unauthorized access to user accounts.…

Q2Root Cause? (CWE/Flaw)

🛡️ **Root Cause**: CWE-862 (Missing Authorization). 🔍 **Flaw**: The plugin fails to verify if the user has permission to perform actions when logging in via phone number.…

Q3Who is affected? (Versions/Components)

👥 **Affected**: WordPress Plugin 'Login with phone number'. 📦 **Versions**: 1.6.93 and earlier. 🏢 **Vendor**: Hamid Alinia. ⚠️ **Scope**: Any site using this specific plugin version.

Q4What can hackers do? (Privileges/Data)

💻 **Privileges**: Full access to user accounts without valid credentials. 📂 **Data**: High risk of Confidentiality (C:H), Integrity (I:H), and Availability (A:H) loss.…

Q5Is exploitation threshold high? (Auth/Config)

📉 **Threshold**: LOW. 🚀 **Auth**: No authentication required (PR:N). 🖱️ **UI**: No user interaction needed (UI:N). 🌐 **Network**: Remote exploitation (AV:N). 🎯 **Complexity**: Low (AC:L). Easy to exploit!

Q6Is there a public Exp? (PoC/Wild Exploitation)

🚫 **Public Exp?**: No specific PoC or wild exploitation code listed in the data. 📄 **References**: Patchstack links provided for verification.…

Q7How to self-check? (Features/Scanning)

🔍 **Self-Check**: Scan for 'Login with phone number' plugin. 📋 **Version**: Check if version ≤ 1.6.93. 🧪 **Test**: Attempt login via phone number without proper session validation.…

Q8Is it fixed officially? (Patch/Mitigation)

🛡️ **Fix**: Update plugin to version > 1.6.93. 📥 **Action**: Download latest patch from official repository. ✅ **Verification**: Ensure authorization checks are implemented for phone login flows.

Q9What if no patch? (Workaround)

🚧 **Workaround**: Disable the 'Login with phone number' feature. 🚫 **Alternative**: Use standard email/password login. 🧱 **Block**: Restrict plugin access via firewall if update is delayed.…

Q10Is it urgent? (Priority Suggestion)

🔥 **Urgency**: HIGH. 🚨 **CVSS**: 9.8 (Critical). ⏳ **Risk**: Immediate exploitation possible due to low barrier. 🏃 **Action**: Patch immediately to prevent account takeover.…