CVE-2023-6520
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2023-6520 is a vulnerability affecting the WP 2FA plugin for WordPress. The issue lies in the plugin's send_backup_codes_email function, which is susceptible to Cross-Site Request Forgery. Unauthenticated attackers can exploit this flaw by forging requests and tricking administrators or registered users into performing an action, such as clicking a link. Despite the presence of a nonce check in the function, it only executes when a nonce is present. By omitting the nonce from the request, the check can be bypassed, allowing attackers to send emails with arbitrary content to registered users. This vulnerability places WordPress sites using the WP 2FA plugin version 2.5.0 and below at risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.