The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/301b3dce-2584-46ec-92ed-1c0626522120 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-10-10 14:15
Updated : 2022-10-11 10:19
NVD link : CVE-2022-2891
Mitre link : CVE-2022-2891
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
wpwhitesecurity
- wp_2fa