Theme My Login 2FA < 1.2 - 2FA Bypass via Brute Force

2023-11-24 00:00
Joost Grunwald

Strategic Overview

Status
Patched in 1.2
Affected PluginTheme My Login 2fa
Affected Version< 1.2
CVSS5.4Medium
CVECVE-2023-6272
View all Theme My Login 2fa vulnerabilities

Vulnerability Overview

The Wordfence Theme My Login 2FA is vulnerable to 2FA brute-forcing in version up to, but excluding, 1.2. This allows unauthenticated attackers to bypass the 2FA protection offered by the plugin.

Technical Analysis

REMEDIATION: Update to version 1.2, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C