WordPress Plugin Vulnerabilities
WP 2FA < 2.2.0 - Arbitrary 2FA Disabling via IDOR
Description
The plugin does not properly check for authorisation when disabling 2FA, allowing users to disable the protection of other users via an IDOR attack
Affects Plugins
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Maycon Vitali
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-04-14 (about 3 years ago)
Added
2022-04-29 (about 3 years ago)
Last Updated
2022-04-29 (about 3 years ago)