WP 2FA – Two-factor authentication for WordPress, CVE-2022-2891
- CVE, Research URL
- Published on
- Oct 11, 2022
- Research Description
- The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.
- Affected versions
-
max 2.2.1.
- Status
-
vulnerable