This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: Critical Auth Bypass in Relais 2FA plugin. ๐ **Consequences**: Attackers can bypass login screens entirely. Full site compromise is imminent. Admin accounts are at risk.โฆ
๐ **CWE**: CWE-288 (Authentication Bypass). ๐ **Flaw**: Incorrect logic in `rl_do_ajax` function. โ **Root Cause**: Missing or flawed capability checks. โ ๏ธ **Result**: Security controls are ignored by the server.
Q3Who is affected? (Versions/Components)
๐ข **Vendor**: mobisoft974. ๐ฆ **Product**: Relais 2FA for WordPress. ๐ **Affected**: Versions **1.0 and earlier**. โ **Safe**: Versions > 1.0 (likely). ๐ **Platform**: WordPress sites using this specific plugin.
Q4What can hackers do? (Privileges/Data)
๐ **Privileges**: Login as **ANY** user. ๐ก๏ธ **Target**: Especially **Administrators**. ๐ง **Requirement**: Attacker needs victim's email. ๐พ **Data**: Full access to site content.โฆ
โก **Threshold**: **LOW**. ๐ซ **Auth**: **Unauthenticated** attack. ๐ฑ๏ธ **UI**: No user interaction needed. ๐ **Network**: Remote exploitation via AJAX. ๐ถ **Ease**: Trivial to execute.
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ป **Exploit**: **Yes**, Public PoC exists. ๐ **Link**: GitHub by RandomRobbieBF. ๐ **Method**: POST request to `admin-ajax.php`. ๐ **Status**: Active exploitation possible. โ ๏ธ **Risk**: High visibility for attackers.
Q7How to self-check? (Features/Scanning)
๐ **Check**: Scan for Relais 2FA plugin. ๐ **Version**: Verify version <= 1.0. ๐ ๏ธ **Tool**: Use WPScan or manual inspection. ๐ **File**: Check `relais.php` logic. ๐ฉ **Flag**: Look for `rl_do_ajax` endpoint.