Vulnerability Undermines WordPress Two-Factor Plugins
ID: 6bca906f-55af-5949-8c88-f30d227d75e4
STIX ID: report--6bca906f-55af-5949-8c88-f30d227d75e4
Feed Name: Security Ledger
Threat Score
Duo Security disclosed a vulnerability in WordPress multisite deployments where certain per-site 2FA plugins (including Duo’s) can be bypassed: a user with valid username/password for one site in a multisite network may be able to log into another site without completing the second-factor. The issue affects multisite configurations only, does not impact single-site deployments, and Duo has contacted WordPress and other plugin publishers to address the bug.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
