WordPress Firebase OTP Authentication plugin <= 1.0.1 - Account Takeover vulnerability
CVE-2024-54294

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 December 2024

What is CVE-2024-54294?

A vulnerability exists in Firebase OTP Authentication developed by Appgenix Infotech that enables attackers to bypass authentication mechanisms through an alternate path or channel. This issue allows unauthorized users to gain access to accounts without the necessary credentials. The vulnerability affects versions from n/a up to and including 1.0.1. Organizations utilizing this product should take immediate steps to address potential security threats, including evaluating their authentication processes and applying relevant patches.

Affected Version(s)

Firebase OTP Authentication 0 <= 1.0.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

stealthcopter (Patchstack Alliance)
.