The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Wordfence
Published: 2023-10-20T07:29:21.001Z
Updated: 2023-10-20T07:29:21.001Z
Reserved: 2023-04-19T14:13:49.149Z
Link: CVE-2022-4943
JSON object: View
NVD Information
Status : Modified
Published: 2023-10-20T08:15:11.983
Modified: 2023-11-07T03:59:23.350
Link: CVE-2022-4943
JSON object: View
Redhat Information
No data.
CWE