Theme My Login 2FA < 1.2 - 2FA Bypass via Brute Force
2023-11-24 00:00
Joost GrunwaldStrategic Overview
StatusPatched in 1.2
Affected PluginTheme My Login 2fa
Affected Version
< 1.2CVSS5.4Medium
CVE
CVE-2023-6272Vulnerability Overview
The Wordfence Theme My Login 2FA is vulnerable to 2FA brute-forcing in version up to, but excluding, 1.2. This allows unauthenticated attackers to bypass the 2FA protection offered by the plugin.
Technical Analysis
REMEDIATION: Update to version 1.2, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C