Description
WordPress Plugin Google Authenticator-Per User Prompt is prone to a timing attack vulnerability because of an implementation flaw in how the application validates the password for a user account. Exploiting this issue may allow attackers to brute force an application password and gain access to the account. WordPress Plugin Google Authenticator-Per User Prompt version 0.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.7 or latest
References
https://hackerone.com/reports/277534
https://plugins.svn.wordpress.org/google-authenticator-per-user-prompt/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WordPress Survey & Poll-Quiz, Survey and Poll SQL Injection (1.1.91)
WordPress Plugin WP htaccess Control Unspecified Vulnerability (2.4)
Oracle Database Server CVE-2013-3774 Vulnerability (CVE-2013-3774)
WordPress Plugin Lazyest Backup 'xml_or_all' Parameter Cross-Site Scripting (0.2.1)