The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/301b3dce-2584-46ec-92ed-1c0626522120 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-10-10 21:15
Updated : 2023-11-07 03:47
NVD link : CVE-2022-2891
Mitre link : CVE-2022-2891
CVE.ORG link : CVE-2022-2891
JSON object : View
Products Affected
wpwhitesecurity
- wp_2fa
CWE
CWE-203
Observable Discrepancy