What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP 2FA: from n/a through 2.6.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP 2FA: from n/a through 2.6.3.
Explanation of Vulnerability in Simple Terms
WP 2FA versions up to 2.6.3 expose sensitive information in log files or error messages without proper access controls. An attacker on the network can read these logs without authentication to obtain partial confidential data. The vulnerability does not allow modification or deletion of data, and no user interaction is required.
What an attacker can do
Read sensitive information from exposed logs or error messages without logging in.
Potential impact on your site
Sensitive data may be exposed to unauthenticated attackers if logs are accessible via the web.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities