The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-12-18T20:07:55.945Z

Updated: 2023-12-18T20:07:55.945Z

Reserved: 2023-11-24T02:55:26.251Z


Link: CVE-2023-6272

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-18T20:15:08.940

Modified: 2023-12-22T18:34:10.253


Link: CVE-2023-6272

JSON object: View

cve-icon Redhat Information

No data.

CWE