CVE-2023-6520

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 11, 2024
Updated: Jan 17, 2024
CWE ID 352

Summary

CVE-2023-6520 is a vulnerability affecting the WP 2FA plugin for WordPress. The issue lies in the plugin's send_backup_codes_email function, which is susceptible to Cross-Site Request Forgery. Unauthenticated attackers can exploit this flaw by forging requests and tricking administrators or registered users into performing an action, such as clicking a link. Despite the presence of a nonce check in the function, it only executes when a nonce is present. By omitting the nonce from the request, the check can be bypassed, allowing attackers to send emails with arbitrary content to registered users. This vulnerability places WordPress sites using the WP 2FA plugin version 2.5.0 and below at risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share