CVE-2023-6272

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:thememylogin:2fa:*:*:*:*:*:wordpress:*:*

History

22 Dec 2023, 18:34

Type Values Removed Values Added
First Time Thememylogin 2fa
Thememylogin
Summary
  • (es) El complemento Theme My Login 2FA de WordPress anterior a 1.2 no limita los intentos de validación de 2FA, lo que puede permitir a un atacante forzar todas las posibilidades con fuerza bruta, lo que no debería ser demasiado largo, ya que los códigos 2FA son de 6 dígitos.
CWE CWE-307
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:thememylogin:2fa:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/a03243ea-fee7-46e4-8037-a228afc5297a - () https://wpscan.com/vulnerability/a03243ea-fee7-46e4-8037-a228afc5297a - Exploit, Third Party Advisory

18 Dec 2023, 20:21

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-18 20:15

Updated : 2023-12-22 18:34


NVD link : CVE-2023-6272

Mitre link : CVE-2023-6272

CVE.ORG link : CVE-2023-6272


JSON object : View

Products Affected

thememylogin

  • 2fa
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts