Cyberus Key

Cyberus Key has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for Cyberus Key has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Pavitra Tiwari. The current release is tested up to WordPress 6.1.12.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Cyberus Key vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2023-28620

Cyberus Key <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'uid' in 'cyberkey_settings' Plugin Setting

Read the full analysis

Vulnerability Records

2 records
Cyberus Key banner
Latestv1.1
0.0(0)
0/100
Last Updated
2023-03-18 (4y ago)
Active Installs
0+
Downloads
1,176
Requires WP
5.4.1+
Requires PHP
7.0+
Tested up to
WP 6.1.12
Created
2021-12-30 (5y ago)

OVERVIEW Cyberus Key solves one of the biggest problems of any online-based human activity responsible for 80% of data breaches – the risk of stolen credentials. We offer a one-touch, 2-factor authentication system for user identification and transaction confirmation. Cyberus Key’s multi-layer, smartphone-based authentication platform offers password-free login that enables businesses and online users to conduct streamlined yet highly secure web-based transactions. Cyberus Key’s unique approach results in a frictionless user experience, streamlined customer acquisition, higher levels of security, the end of passwords. HOW DOES IT WORK? User perspective Download our Android or iOS application and register. Remember to use the same email address as you do on your wordpress website. On your wordpress site login page (/wp-login.php), instead of the traditional login/password, click the “Login with CyberusKey” widget. The One-Time token is transmitted to mobile app via sound, no need to type anything! You are authenticated on the website and logged in. SYSTEM OWNER PERSPECTIVE – INTEGRATION STEPS Download our Android or iOS mobile application and register. Follow steps presented on our integration form [here][https://loginwithoutpasswords.com/integration/] On the Integration tab on our website create a redirection: YOUR_SITE_URL +’/wp-json/api/login’ e.g. https://example.com/wp-json/api/login Copy Client Id and Client Secret for later usage Once you download and activate this plugin, go to settings and paste Client Id and Secret into appropriate fields. Done. You can change to Users perspective to see how it works. For additional information about the logins performed on your website visit cyberuskey.com

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C