T
he miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/d70c5335-4c01-448d-85fc-f8e75b104351 | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/d70c5335-4c01-448d-85fc-f8e75b104351 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 06:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://wpscan.com/vulnerability/d70c5335-4c01-448d-85fc-f8e75b104351 - Exploit, Third Party Advisory |
Information
Published : 2022-03-21 19:15
Updated : 2024-11-21 06:38
NVD link : CVE-2022-0229
Mitre link : CVE-2022-0229
CVE.ORG link : CVE-2022-0229
JSON object : View
Products Affected