9.8
CVSSv3

CVE-2023-6272

Published: 18/12/2023 Updated: 22/12/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Theme My Login 2FA WordPress plugin prior to 1.2 does not rate limit 2FA validation attempts, which may allow an malicious user to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

Vulnerable Product Search on Vulmon Subscribe to Product

thememylogin 2fa