VendorsminiOrangegoogle_authenticatorall versions
Vulnerabilities

miniOrange Google Authenticator 1.0.5 for WordPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-42461
WordPress miniOrange's Google Authenticator plugin <= 5.6.1 - Broken Access Control vulnerability
Published 2022-11-18 · Modified
8.8EPSS 0.007
CVE-2022-44589
WordPress miniOrange's Google Authenticator Plugin <= 5.6.1 is vulnerable to Sensitive Data Exposure
Published 2023-12-29 · Modified
8.1EPSS 0.007
CVE-2022-0229
miniOrange's Google Authenticator < 5.5 - Unauthenticated Arbitrary Options Deletion
Published 2022-03-21 · Modified
8.1EPSS 0.006
CVE-2022-4943
miniOrange's Google Authenticator <= 5.6.5 - Missing Authorization to Plugin Settings Change
Published 2023-10-20 · Modified
7.5EPSS 0.005
CVE-2022-1321
miniOrange's Google Authenticator < 5.5.6 - Admin+ Stored Cross-Site Scripting
Published 2022-06-27 · Modified
4.8EPSS 0.006
CVE-2022-0875
miniOrange Google Authenticator < 1.0.5 - CSRF to Stored Cross-Site Scripting
Published 2022-06-27 · Modified
4.3EPSS 0.004