CVE-2024-9820

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 15, 2024
Updated: Oct 19, 2024
CWE ID 784
CWE ID 565

Summary

CVE-2024-9820 is a vulnerability affecting the WP 2FA with Telegram plugin for WordPress. In versions up to 3.0, the plugin stores the two-factor authentication code in a cookie instead of deleting it after use. This weakness enables an attacker to bypass two-factor authentication checks, compromising the secured WordPress accounts. Users are advised to update their plugin versions to mitigate this risk and employ stronger security measures, such as using unique and complex passwords, to safeguard their accounts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share