miniOrange's Google Authenticator <= 5.4.52 - Unauthenticated Arbitrary Options Deletion

2022-02-28 00:00
Krzysztof Zając

Vulnerability Overview

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

Technical Analysis

REMEDIATION: Update to version 5.5, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C