Insecure Direct Object Reference in WP 2FA Two-Factor Authentication Plugin for WordPress
CVE-2023-6506
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 January 2024
What is CVE-2023-6506?
The WP 2FA – Two-factor authentication for WordPress plugin is susceptible to an Insecure Direct Object Reference, allowing unauthenticated users with subscriber roles to exploit the send_backup_codes_email function. This vulnerability arises from insufficient validation on user-controlled keys, potentially enabling malicious subscribers to send arbitrary emails to any user on the site. All versions up to and including 2.5.0 are affected, creating significant risks for user data privacy.
Affected Version(s)
WP 2FA – Two-factor authentication for WordPress * <= 2.5.0