Description
WordPress Plugin Duo Two-Factor Authentication is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and gain unauthorized access to the affected application. The vulnerability exists only in multi-site deployments scenario with the plugin disabled globally and enabled on a site-by-site basis. WordPress Plugin Duo Two-Factor Authentication version 1.8.1 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 2.0 or latest
References
Related Vulnerabilities
ReviveAdserver Other Vulnerability (CVE-2014-8875)
PrestaShop Improper Input Validation Vulnerability (CVE-2023-39530)
WordPress Plugin Social Login Lite For WooCommerce Security Bypass (1.6.0)
MediaWiki Other Vulnerability (CVE-2004-1405)
WordPress Plugin Elementor Website Builder Multiple Vulnerabilities (3.16.4)