External risk intelligence

Login with phone number Missing Authorization Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2024-32832

The vulnerability affects a WordPress plugin designed for user authentication via phone number. Such plugins are typically installed on public-facing websites to handle user login and registration flows, making the vulnerable code path directly reachable over the internet by any user or visitor.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in the "Login with phone number" functionality, specifically impacting how user access is authorized. This vulnerability could allow unauthorized individuals to gain elevated privileges within systems that utilize this login method, potentially leading to significant data compromise. The primary concern at this stage is to determine if our environment utilizes this specific, vulnerable functionality.

  • Flaw allows unauthorized system access.
  • Critical flaw in phone number login.
  • Confirm use and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could reach the vulnerable component by accessing a website that uses the "Login with phone number" plugin. Since no authentication is required to interact with this plugin, an unauthenticated attacker can target the login functionality. The vulnerability lies in the plugin's handling of authorization, which an attacker could exploit to potentially gain unauthorized access to user accounts.

  • No authentication required.
  • Targets the plugin's login function.
  • Enables unauthorized account access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to bypass authorization controls when a user logs in with a phone number, potentially enabling unauthorized access to sensitive system data or user information. This exposure may occur when the affected login functionality is accessed.

  • Unauthorized access to user accounts.
  • Bypass authentication controls.
  • Compromise of system data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Login with phone number plugin requires immediate attention from the platform or infrastructure team responsible for managing WordPress deployments. The first step is to identify all instances of the affected plugin, confirm their network exposure, and assess business criticality. Once identified, work with the application owner to plan and execute remediation, prioritizing systems with direct external access or those handling sensitive authentication functions.

  • Platform/Infrastructure team owns remediation.
  • Verify plugin presence and network exposure.
  • Coordinate owner-based remediation planning.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Login with phone number plugin?

Login with phone number is a WordPress plugin that enables website visitors to authenticate or register using their mobile phone numbers instead of traditional email-based credentials. It typically integrates directly into a site's login and sign-up forms to streamline user entry processes.

What does CWE-862 mean for CVE-2024-32832?

CWE-862 refers to a Missing Authorization weakness. In the context of CVE-2024-32832, it means the plugin fails to properly verify if a user has the correct permissions before performing sensitive actions. Because the software skips these authorization checks, an attacker can potentially access or modify data that should be restricted.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by interacting with the plugin's login functions from a web browser. Because the vulnerability involves missing authorization, no valid user credentials or prior account access are needed to reach the faulty code path. Simply navigating to the site's login page is sufficient; standard, legitimate user actions do not trigger the bug.

Is my website at risk if I use this plugin?

According to Halo Surface Signal, this plugin is typically installed on public-facing websites, making the vulnerable code directly reachable over the internet. If your site uses this plugin to handle authentication flows, it is considered internet-facing and highly relevant for review.

How should I respond to CVE-2024-32832?

Start by auditing your WordPress environments to identify where the Login with phone number plugin is installed. Once you have a list of affected sites, verify which ones are accessible from the internet. Coordinate with your application owners to plan remediation, prioritizing systems that manage sensitive user accounts or personal information.

References