PT-2024-16135 · WordPress · Relais 2Fa

István Márton

·

Published

2024-11-12

·

Updated

2024-11-17

·

CVE-2024-10245

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Relais 2FA plugin for WordPress versions up to, and including, 1.0
Description The issue is due to incorrect authentication and capability checking in the rl do ajax function, allowing unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Recommendations For Relais 2FA plugin for WordPress versions up to, and including, 1.0, consider disabling the rl do ajax function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10245

Affected Products

Relais 2Fa