CVE-2022-42461: WordPress miniOrange's Google Authenticator plugin <= 5.6.1 - Broken Access Control vulnerability
Published Nov 18, 2022
·Updated
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
Affected Software
1 affected component
miniOrange Google Authenticator WordPress<5.6.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress miniOrange's Google Authenticator pluginto a version that resolves this vulnerability.Fixed in 5.6.2
Event History
Nov 18, 2022
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-42461?
CVE-2022-42461 is a Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
2
What is the severity of CVE-2022-42461?
CVE-2022-42461 has a severity rating of 8.8 (High).
3
Which software versions are affected by CVE-2022-42461?
CVE-2022-42461 affects versions up to and including 5.6.1 of miniOrange's Google Authenticator plugin on WordPress.
4
How can I fix CVE-2022-42461?
To fix CVE-2022-42461, update your miniOrange's Google Authenticator plugin to version 5.6.2 or higher.
5
What is the CWE ID for CVE-2022-42461?
The CWE ID for CVE-2022-42461 is 264.