Lucene search

K
cvelistWPScanCVELIST:CVE-2022-0229
HistoryMar 21, 2022 - 6:55 p.m.

CVE-2022-0229 miniOrange's Google Authenticator < 5.5 - Unauthenticated Arbitrary Options Deletion

2022-03-2118:55:42
WPScan
www.cve.org
6
miniorange google authenticator unauthenticated deletion csrf check validation plugin wordpress

EPSS

0.001

Percentile

40.0%

The miniOrange’s Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "miniOrange's Google Authenticator",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "5.5"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

EPSS

0.001

Percentile

40.0%

Related for CVELIST:CVE-2022-0229