Описание
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
EPSS
Процентиль: 10%
0.00202
Низкий
7.5 High
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 7.5
github
8 дней назад
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
EPSS
Процентиль: 10%
0.00202
Низкий
7.5 High
CVSS3
Дефекты
CWE-287