Strategic Overview
- Status
- Patched in 1.2
- Affected Plugin
- Theme My Login 2fa
- Affected Version
< 1.2- CVSS
- 5.4Medium
- Weakness type
- CWE-693 · Protection Mechanism Failure
- CVE
CVE-2023-6272
At a glance
CVE-2023-6272 is a medium-severity Protection Mechanism Failure vulnerability in the Theme My Login 2fa WordPress plugin, affecting versions < 1.2. It carries a CVSS score of 5.4 (reachable over the network; low attack complexity). The issue is fixed in version 1.2; sites on affected versions should update now. Disclosed November 2023, reported by Joost Grunwald.
Vulnerability Overview
The Wordfence Theme My Login 2FA is vulnerable to 2FA brute-forcing in version up to, but excluding, 1.2. This allows unauthenticated attackers to bypass the 2FA protection offered by the plugin.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.
CWE-693: Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Remediation
Update to version 1.2, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: Theme My Login 2fa 1.2 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C