MFA Bypass Vulnerability in WP Cerber Security Plugin by WordPress
CVE-2021-37597
9.8CRITICAL
What is CVE-2021-37597?
The WP Cerber Security Plugin prior to version 8.9.3 is susceptible to a vulnerability that allows unauthorized users to bypass multi-factor authentication. This is achieved through manipulation of the 'wordpress_logged_in_[hash]' parameter, potentially allowing attackers to gain access to accounts without proper authentication. It is essential for users to update to the latest version to mitigate this security risk.