Skip to main content

Threat intelligence

miniOrange's Google Authenticator <= 5.4.52 - Unauthenticated Arbitrary Options Deletion

CVE-2022-0229 · miniorange-2-factor-authentication

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Miniorange 2 Factor Authentication at a vulnerable version. How SiteRespond intelligence works

Vulnerability
miniOrange's Google Authenticator <= 5.4.52 - Unauthenticated Arbitrary Options Deletion
Affected software
miniorange-2-factor-authentication(Plugin)
Affected versions
  • ≤ 5.4.52
Authentication
Unauthenticated
Vulnerability type
Other
Published
28 February 2022
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory f53875aa-9347-464c-aaeb-e8248628fca2). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Miniorange 2 Factor Authentication version against this catalog when the Defence plugin is connected to your WordPress site.