WebAuthn Provider for Two Factor是一款双因素认证的WebAuthn提供程序。 WordPress WebAuthn Provider for Two Factor 2.5.6之前版本存在授权问题漏洞,该漏洞源于未能正确验证第二因素身份验证响应,可能导致已知用户密码的攻击者通过提交恶意请求绕过双因素身份验证要求。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WebAuthn Provider for Two Factor | < 2.5.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WebAuthn Provider for Two Factor | 0 ~ 2.5.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11568 | Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data | |
| CVE-2026-11562 | WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update | |
| CVE-2026-11570 | User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name | |
| CVE-2026-11794 | Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Fo | |
| CVE-2026-10750 | Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools | |
| CVE-2026-11887 | Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass | |
| CVE-2026-11880 | Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR |
No comments yet