漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa
Vulnerability Description
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
cleverplugins Security Ninja – WordPress Security & Firewall 授权问题漏洞
Vulnerability Description
cleverplugins Security Ninja – WordPress Security & Firewall是cleverplugins个人开发者的WordPress安全与防火墙插件。 cleverplugins Security Ninja – WordPress Security & Firewall 5.290之前版本存在授权问题漏洞,该漏洞源于未验证双因素身份验证中的第二个身份验证因素,导致知道用户密码的未经验证攻击者无需一次性代码即可完成身份验证,绕过强制双因素身份验证。
CVSS Information
N/A
Vulnerability Type
N/A