CVE-2024-9820CWE-784
WP 2FA with Telegram <= 3.0 - Two-Factor Authentication Bypass
Medium · published October 15, 2024
What it is
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.
The record
Technical detail
- CVSS v3.1
- 6.5 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00402 · 33.5th percentile
- Weakness
- CWE-784 · Reliance on Cookies without Validation and Integrity Checking in a Security Decision
- Published
- 2024-10-15T02:03Z
EPSS history
Timeline