VDB
CVE-2022-4943
CVE-2022-4943
PUBLISHED
CVSS 7.5 HIGH
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.
EPSS 0.54% · 44.5th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.54%
44.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| miniorange | google_authenticator | 0 |
| cyberlord92 | miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA , Two Factor, OTP SMS and Email | Passwordless login | * |
Timeline
- Oct 20, 2023 EPSS Score
- Oct 20, 2023 CVE Published
- Nov 20, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
- Jan 22, 2024 EPSS Score
- Mar 25, 2024 EPSS Score
- Apr 26, 2024 EPSS Score
- May 27, 2024 EPSS Score
- Jun 28, 2024 EPSS Score
- Jul 29, 2024 EPSS Score
- Aug 30, 2024 EPSS Score
- Sep 30, 2024 EPSS Score
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/7267ede1-7745-47cc-ac0d-4362140b4c23?source=cve url
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2842228%40miniorange-2-factor-authentication%2Ftrunk&old=2815645%40miniorange-2-factor-authentication%2Ftrunk&sfp_email=&sfph_mail= url
- https://nvd.nist.gov/vuln/detail/CVE-2022-4943 advisory