Input validation vulnerability in Two Factor Authentication (2FA , MFA, OTP SMS and Email) 1.0.7

The Two Factor Authentication plugin for WordPress is vulnerable to a type of attack in versions up to 1.0.7. This attack is called Reflected Cross-Site Scripting and it happens when an unauthenticated attacker can inject web scripts through the ‘user’ parameter. This can happen if a user clicks on a link without realizing it. These scripts would then be executed on the user’s computer. It is important to update to the latest version of the Two Factor Authentication plugin to protect yourself against this attack.

Detected in:

Two Factor Authentication (2FA , MFA, OTP SMS and Email) fixed vulnerable versions: >= * <= 1.0.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.