PT-2026-54499 · WordPress · Webauthn Provider For Two Factor
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WebAuthn Provider for Two Factor WordPress plugin versions prior to 2.5.6
Description
An issue exists where the plugin fails to correctly validate the second-factor authentication response. This allows an attacker who has already obtained a user's password to bypass the two-factor authentication requirement by submitting a malformed request.
Recommendations
Update the plugin to version 2.5.6 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webauthn Provider For Two Factor