The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.
Metrics
Affected Vendors & Products
References
History
Sat, 19 Oct 2024 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dueclic
Dueclic wp 2fa With Telegram |
|
Weaknesses | CWE-565 | |
CPEs | cpe:2.3:a:dueclic:wp_2fa_with_telegram:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Dueclic
Dueclic wp 2fa With Telegram |
Tue, 15 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 15 Oct 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication. | |
Title | WP 2FA with Telegram <= 3.0 - Two-Factor Authentication Bypass | |
Weaknesses | CWE-784 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-15T02:03:53.185Z
Updated: 2024-10-15T13:41:01.850Z
Reserved: 2024-10-10T14:24:51.483Z
Link: CVE-2024-9820
Vulnrichment
Updated: 2024-10-15T13:40:54.368Z
NVD
Status : Analyzed
Published: 2024-10-15T02:15:03.170
Modified: 2024-10-19T00:44:10.420
Link: CVE-2024-9820
Redhat
No data.