Showing 1 vulnerability on this page for miniOrange 2FA – Two-Factor Authentication for WordPress (SMS, Email & Google Authenticator)

Signals CISA KEV Ransomware Nuclei
cyberlord92 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

miniOrange's Google Authenticator <= 5.6.5 - Missing Authorization to Plugin Settings Change

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.

CWE-862Oct 20, 2023
CVSS7.5v3.1EPSS0.543%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX