First published: Mon Jun 27 2022(Updated: )
The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Miniorange Login With Otp Over Sms, Email, Whatsapp And Google Authenticator | <1.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Login With OTP Over SMS Email WhatsApp and Google Authenticator plugin is CVE-2022-1994.
The severity of CVE-2022-1994 is medium.
The affected software for CVE-2022-1994 is the Miniorange Login With Otp Over Sms, Email, Whatsapp And Google Authenticator plugin before version 1.0.8.
The CWE ID for CVE-2022-1994 is CWE-79.
To fix CVE-2022-1994, update the Login With OTP Over SMS Email WhatsApp and Google Authenticator plugin to version 1.0.8 or later.