plugin

Miniorange Google Authenticator Vulnerabilities

4 known security issues reported for the Miniorange Google Authenticator WordPress plugin. Most recent disclosed Jun 27, 2022.

1 critical 1 medium

Running Miniorange Google Authenticator on your site? Check whether your installed version is affected.

Scan your site free

Login with TOTP (Google Authenticator, Microsoft Authenticator) [miniorange-google-authenticator] < 1.0.5 (unfixed + closed)

unknown

[en] The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

Affected:
up to 1.0.5
Fix:
No patched version reported
Disclosed:
Jun 27, 2022

CVE-2022-0875 on NVD →

Login with TOTP (Google Authenticator, Microsoft Authenticator) [miniorange-google-authenticator] < 1.0.8 (closed)

unknown

[en] The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Jun 27, 2022

CVE-2022-1994 on NVD →

Login With OTP Over SMS, Email, WhatsApp and Google Authenticator <= 1.0.4 - Cross-Site Request Forgery to Cross-Site Scripting

critical

The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

CVSS:
9.6
Affected:
up to 1.0.4
Fixed in:
1.0.5
Disclosed:
Jun 6, 2022

CVE-2022-0875 on NVD →

Login With OTP Over SMS, Email, WhatsApp and Google Authenticator <= 1.0.7 - Cross-Site Scripting

medium

The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVSS:
4.8
Affected:
up to 1.0.7
Fixed in:
1.0.8
Disclosed:
Jun 6, 2022

CVE-2022-1994 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database