Extension WordPress

Vulnérabilités Login with TOTP (Google Authenticator, Microsoft Authenticator)

Cette page rassemble les failles publiées pour Login with TOTP (Google Authenticator, Microsoft Authenticator), leurs plages de versions affectées et les correctifs signalés dans la base locale.

2Vulnérabilités
1Critiques
2Avec correctif
9,6CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Login with TOTP (Google Authenticator, Microsoft Authenticator)

2 fiches

CVE-2022-1994 Moyenne · 4,8
Login with TOTP (Google Authenticator, Microsoft Authenticator)

Login With OTP Over SMS, Email, WhatsApp and Google Authenticator <= 1.0.7 – Cross-Site Scripting

The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

Versions affectées

*-1.0.7

Correctif

1.0.8

Publication

06/06/2022

CVE-2022-0875 Critique · 9,6
Login with TOTP (Google Authenticator, Microsoft Authenticator)

Login With OTP Over SMS, Email, WhatsApp and Google Authenticator <= 1.0.4 – Cross-Site Request Forgery to Cross-Site Scripting

The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site…

Versions affectées

*-1.0.4

Correctif

1.0.5

Publication

06/06/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités