CVE-2022-1994: Google Authenticator < 1.0.8 - Admin+ Stored Cross-Site Scripting
Published Jun 27, 2022
·Updated
The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfilteredhtml is disallowed
Affected Software
1 affected component
miniOrange Login With Otp Over Sms\, Email\, Whatsapp And Google Authenticator Wordpress<1.0.8
Event History
Jun 27, 2022
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Login With OTP Over SMS Email WhatsApp and Google Authenticator plugin?
The vulnerability ID for the Login With OTP Over SMS Email WhatsApp and Google Authenticator plugin is CVE-2022-1994.
2
What is the severity of CVE-2022-1994?
The severity of CVE-2022-1994 is medium.
3
What is the affected software for CVE-2022-1994?
The affected software for CVE-2022-1994 is the Miniorange Login With Otp Over Sms, Email, Whatsapp And Google Authenticator plugin before version 1.0.8.
4
What is the CWE ID for CVE-2022-1994?
The CWE ID for CVE-2022-1994 is CWE-79.
5
How can I fix CVE-2022-1994?
To fix CVE-2022-1994, update the Login With OTP Over SMS Email WhatsApp and Google Authenticator plugin to version 1.0.8 or later.