CVE-2022-44589

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
29/12/2023
Last modified:
28/04/2026

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA , Two Factor, OTP SMS and Email | Passwordless login.This issue affects miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA , Two Factor, OTP SMS and Email | Passwordless login: from n/a through 5.6.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:miniorange:google_authenticator:*:*:*:*:*:wordpress:*:* 5.6.2 (excluding)