Description
WordPress Plugin Google Authenticator-Per User Prompt is prone to a timing attack vulnerability because of an implementation flaw in how the application validates the password for a user account. Exploiting this issue may allow attackers to brute force an application password and gain access to the account. WordPress Plugin Google Authenticator-Per User Prompt version 0.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.7 or latest
References
https://hackerone.com/reports/277534
https://plugins.svn.wordpress.org/google-authenticator-per-user-prompt/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Tune Library 'letter' Parameter SQL Injection (1.5.1)
WordPress Plugin Geo Mashup Unspecified Vulnerability (1.10.3)
PHP Out-of-bounds Read Vulnerability (CVE-2019-11050)
WordPress Plugin SecureMoz Security Audit PHP Object Injection (1.0.5)
Oracle Application Server CVE-2008-2609 Vulnerability (CVE-2008-2609)