WordPress Plugin Vulnerabilities

WP 2FA < 2.6.0 - Arbitrary Email Sending via CSRF

Description

The plugin has a flawed CSRF check when sending emails to registered users, which could allow attackers to make logged in admins perform such action via a CSRF attack

Affects Plugins

Fixed in 2.6.0

References

Classification

Miscellaneous

Original Researcher
Ulyses Saicha
Verified
No

Timeline

Publicly Published
2024-01-02 (about 2 years ago)
Added
2024-01-03 (about 2 years ago)
Last Updated
2024-01-03 (about 2 years ago)

Other