CyberRota Analysis
AI-GeneratedThe Google Authenticator WordPress plugin prior to version 0.56 is vulnerable due to a lack of CSRF nonce verification when saving two-factor authentication settings. This flaw allows attackers to manipulate a logged-in user's 2FA setup, potentially locking them out of their account by replacing their authentication secret with a malicious one. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of account takeover.
Original NVD Description
The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account.