VYPR
Unrated severityNVD Advisory· Published Mar 21, 2022· Updated Aug 2, 2024

miniOrange's Google Authenticator < 5.5 - Unauthenticated Arbitrary Options Deletion

CVE-2022-0229

Description

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.