What the vulnerability does
01Description
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
Explanation of Vulnerability in Simple Terms
The miniOrange Google Authenticator WordPress plugin version 5.6.1 and earlier contains a flaw that allows authenticated users to modify plugin settings and disable security features. An attacker with low-level WordPress access can alter configuration without proper authorization checks, potentially weakening two-factor authentication enforcement across the site.
What an attacker can do
Modify plugin settings and disable two-factor authentication features.
Potential impact on your site
Two-factor authentication can be disabled by low-privilege users, reducing account security across your site.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (subscriber or above).
Key dates
External resources
Related vulnerabilities