CVE-2022-0229: miniOrange's Google Authenticator < 5.5 - Unauthenticated Arbitrary Options Deletion
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-0229.
What is the severity of CVE-2022-0229?
The severity of CVE-2022-0229 is high with a severity value of 8.1.
What is the affected software by CVE-2022-0229?
The affected software is the miniOrange's Google Authenticator WordPress plugin version up to and excluding 5.5.
What are the potential consequences of CVE-2022-0229?
CVE-2022-0229 allows unauthenticated users to delete arbitrary options from the blog, compromising its security.
How can I mitigate CVE-2022-0229?
To mitigate CVE-2022-0229, update the miniOrange's Google Authenticator WordPress plugin to version 5.5 or later.