High severity7.5NVD Advisory· Published Oct 20, 2023· Updated Apr 8, 2026
CVE-2022-4943
CVE-2022-4943
Description
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.
Affected products
1- cpe:2.3:a:miniorange:google_authenticator:*:*:*:*:*:wordpress:*:*Range: <=5.6.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/7267ede1-7745-47cc-ac0d-4362140b4c23nvdThird Party Advisory
- plugins.trac.wordpress.org/changesetnvdProduct
News mentions
0No linked articles in our index yet.