CVE-2024-9820CWE-784

WP 2FA with Telegram <= 3.0 - Two-Factor Authentication Bypass

Medium · published October 15, 2024

CVSS v3.1
6.5
EPSS
0%
Percentile
33.5
In the wild
Unconfirmed
What it is

The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00402 · 33.5th percentile
Weakness
CWE-784 · Reliance on Cookies without Validation and Integrity Checking in a Security Decision
Published
2024-10-15T02:03Z
EPSS history
Timeline
  • 15 OCT 02:03Z
    WP 2FA with Telegram <= 3.0 - Two-Factor Authentication Bypass
    cvelistv5