Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High2
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2024-11-21

CVE-2024-5324 - Otp Login Woocommerce Gravity Forms Plugin

The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

PLUGIN Otp Login Woocommerce Gravity Forms

CVE-2024-5324

HIGH CVSS 8.8 2024-06-06
Threat Entry Updated 2024-11-21

CVE-2023-2706 - Otp Login Woocommerce Gravity Forms Plugin

The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to obtain login codes for administrators. This does require an attacker have access to the phone number configured for an account, which can be obtained via social engineering or reconnaissance.

PLUGIN Otp Login Woocommerce Gravity Forms

CVE-2023-2706

HIGH CVSS 8.1 2023-05-17
Scroll to top