First published: Mon Jun 27 2022(Updated: )
The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Miniorange Google Authenticator | <1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0875 is a vulnerability in the Google Authenticator WordPress plugin before version 1.0.5 that allows attackers to perform Cross-Site Scripting (XSS) attacks.
CVE-2022-0875 has a severity level of medium, with a CVSS score of 4.3.
CVE-2022-0875 affects the Google Authenticator WordPress plugin before version 1.0.5 by allowing attackers to make a logged-in admin change the plugin's settings and potentially perform XSS attacks.
To fix CVE-2022-0875 in the Google Authenticator WordPress plugin, update to version 1.0.5 or later, which includes a CSRF check when saving settings and sanitization/escaping of inputs.
Yes, you can find additional information about CVE-2022-0875 at the following reference link: [CVE-2022-0875 Reference](https://wpscan.com/vulnerability/fefc1411-594d-465b-aeb9-78c141b23762)