miniOrange's Google Authenticator <= 5.4.52 - Unauthenticated Arbitrary Options Deletion
2022-02-28 00:00
Krzysztof ZającStrategic Overview
StatusPatched in 5.5
Affected PluginminiOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator)
Affected Version
<= 5.4.52CVSS8.1High
CVE
CVE-2022-0229Vulnerability Overview
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.
Technical Analysis
REMEDIATION: Update to version 5.5, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C