Skip to main content

Threat intelligence

miniOrange's Google Authenticator <= 5.6.1 - Cross-Site Request Forgery to Malware Scan Termination

miniorange-2-factor-authentication · No CVE assigned

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Miniorange 2 Factor Authentication at a vulnerable version. How SiteRespond intelligence works

Vulnerability
miniOrange's Google Authenticator <= 5.6.1 - Cross-Site Request Forgery to Malware Scan Termination
Affected software
miniorange-2-factor-authentication(Plugin)
Affected versions
  • ≤ 5.6.1
Authentication
Not specified in feed title — see source advisory
Vulnerability type
CSRF
CVE
Not assigned
Published
1 November 2022
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
May trick authenticated users into performing unintended actions.
Source

Data imported from Wordfence Intelligence (advisory ed117fb8-c13a-4088-aa33-8d44fc5dcf37). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Miniorange 2 Factor Authentication version against this catalog when the Defence plugin is connected to your WordPress site.