Описание
The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2 (исключая)
cpe:2.3:a:thememylogin:2fa:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 61%
0.00407
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-307
Связанные уязвимости
CVSS3: 9.8
github
около 2 лет назад
The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.
EPSS
Процентиль: 61%
0.00407
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-307