CVE-2024-10245

NVD Published Date: November 12, 2024 at 10:15 AM
NVD Last Modified: November 12, 2024 at 01:55 PM
Download Patch
Vulnerability ID
CVE-2024-10245
Severity
CRITICAL
Severity Score
9.8
Summary
The Relais 2FA plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0. This is due to incorrect authentication and capability checking in the 'rl_do_ajax' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Mitigation and Patches
-
Exploits
-
Metasploit Payload
-
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE ID
CWE-288

Recent Publish

CVE-2024-9998

KB5041770

KB5041773

CVE-2024-11067

CVE-2024-11021

KB5041782

See More ...

See SecOps Solution
in action

Schedule Demo