WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://github.com/fireeye/Vulnerability-Disclosures | third party advisory |
https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0023/FEYE-2021-0023.md | third party advisory exploit |