Cross-Site Scripting Vulnerability in Two-Factor Authentication Plugin for WordPress
CVE-2015-9355
6.1MEDIUM
What is CVE-2015-9355?
The Two-Factor Authentication plugin for WordPress, prior to version 1.1.10, contains a cross-site scripting (XSS) vulnerability in its admin area. This flaw can allow authenticated users to inject malicious scripts, compromising the security of the website. It underscores the importance of keeping plugins updated to mitigate potential threats and protect sensitive information.