CVE-2024-9820
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS probability
- 0.40%
- CWE
- CWE-784
- Published
- 2024-10-15
- Last modified
- 2026-04-09
Affected products
- dueclic WP 2FA with Telegram
- dueclic AuthPress
Weakness type
Related vulnerabilities
- CVE-2026-60134 — Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision
- CVE-2026-45055 — CubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host Header