Impact
A CSRF vulnerability exists in the ipv_save_changes function of the Two‑factor authentication (formerly IP Vault) WordPress plugin because nonce validation is missing or incorrect. The flaw lets an unauthenticated actor craft a request that, when sent by a site administrator, modifies critical security settings such as the firewall rules, authentication mode, slug and log retention period. This can effectively turn off the plugin’s protections, leaving the site vulnerable to a range of attacks. The weakness is a typical CSRF (CWE‑352).
Affected Systems
All versions of the WordPress plugin Two‑factor authentication (formerly IP Vault) up to and including 2.1, distributed by youtag, are affected. Sites running these versions should review whether the plugin is in use and upgrade as soon as a fixed release is available.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. Because the flaw is a CSRF that requires the victim to act on a forged link, the likelihood of exploitation depends on the attacker’s ability to trick a site administrator; the EPSS score is not available and the vulnerability is not yet listed in KEV. No public exploits are documented, but the impact if successful would disable two‑factor authentication and firewall controls.
OpenCVE Enrichment