CVE-2024-9820
MEDIUMDescription
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.
Is your site exposed to CVE-2024-9820?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| dueclic | wp_2fa_with_telegram |
References
Frequently Asked Questions
What is CVE-2024-9820? +
How severe is CVE-2024-9820? +
What products are affected by CVE-2024-9820? +
How do I check if I'm vulnerable to CVE-2024-9820? +
Related Vulnerabilities
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request …
The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. …