VDB
CVE-2022-0229
CVE-2022-0229
PUBLISHED
CVSS 8.100000381469727 HIGH
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.
EPSS 0.55% · 44.9th percentile
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
EPSS Score
0.55%
44.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unknown | miniOrange's Google Authenticator | 0 |
| miniorange | google_authenticator | 0 |
Timeline
- Mar 21, 2022 CVE Published
- Mar 22, 2022 EPSS Score
- May 12, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Oct 15, 2022 EPSS Score
- Dec 5, 2022 EPSS Score
- Jan 25, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 18, 2023 EPSS Score
- May 8, 2023 EPSS Score
- Aug 19, 2023 EPSS Score
- Oct 9, 2023 EPSS Score