CVE-2022-44587: WordPress WP 2FA plugin <= 2.6.3 - Sensitive Data Exposure via Log File vulnerability
Published Jun 21, 2024
·Updated
Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP 2FA: from n/a through 2.6.3.
Affected Software
1 affected component
Melapress Wp 2fa Wordpress<2.6.4
Remediation
Information
Update to 2.6.4 or a higher version.
Event History
Jun 21, 2024
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-44587?
CVE-2022-44587 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-44587?
To fix CVE-2022-44587, upgrade the WP 2FA plugin to version 2.6.4 or higher.
3
What systems are affected by CVE-2022-44587?
CVE-2022-44587 affects WP 2FA versions up to 2.6.3.
4
What type of vulnerability is CVE-2022-44587?
CVE-2022-44587 is an Insertion of Sensitive Information into Log File vulnerability.
5
What can attackers do with CVE-2022-44587?
Attackers can access functionality not properly constrained by ACLs due to CVE-2022-44587.