Description
WordPress Plugin Duo Two-Factor Authentication is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and gain unauthorized access to the affected application. The vulnerability exists only in multi-site deployments scenario with the plugin disabled globally and enabled on a site-by-site basis. WordPress Plugin Duo Two-Factor Authentication version 1.8.1 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 2.0 or latest
References
Related Vulnerabilities
WordPress Plugin Simple Events Calendar SQL Injection (1.4.0)
WordPress Plugin Arlo training and event management system Cross-Site Scripting (2.1.7.1)
WordPress Plugin Timetable and Event Schedule by MotoPress Information Disclosure (2.3.19)
Drupal Core 6.x Multiple Vulnerabilities (6.0 - 6.8)
WordPress Plugin WP Cost Estimation & Payment Forms Builder Multiple Vulnerabilities (9.642)