CVE-2024-9820
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 15, 2024
Updated: Oct 19, 2024
CWE ID 784
CWE ID 565
Summary
CVE-2024-9820 is a vulnerability affecting the WP 2FA with Telegram plugin for WordPress. In versions up to 3.0, the plugin stores the two-factor authentication code in a cookie instead of deleting it after use. This weakness enables an attacker to bypass two-factor authentication checks, compromising the secured WordPress accounts. Users are advised to update their plugin versions to mitigate this risk and employ stronger security measures, such as using unique and complex passwords, to safeguard their accounts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.