PT-2022-5018 · WordPress · Wp 2Fa

Calvin Alkan

·

Published

2022-09-14

·

Updated

2023-08-02

·

CVE-2022-2891

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP 2FA WordPress plugin versions prior to 2.3.0
Description The issue exists due to the use of comparison operators that do not mitigate time-based attacks, potentially allowing a remote attacker to leak information about authentication codes being compared. This could facilitate inter-site script attacks.
Recommendations For WP 2FA WordPress plugin versions prior to 2.3.0, update to version 2.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to authentication code comparison functions until a patch is available.

Exploit

Fix

Information Disclosure

Side Channel Attack

Weakness Enumeration

Related Identifiers

BDU:2022-06231
CVE-2022-2891

Affected Products

Wp 2Fa