Description
The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-35120 | The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T00:53:00.501Z
Reserved: 2022-08-18T00:00:00.000Z
Link: CVE-2022-2891
No data.
Status : Modified
Published: 2022-10-10T21:15:10.877
Modified: 2024-11-21T07:01:52.927
Link: CVE-2022-2891
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD