Vulnerabilities > Thememylogin

DATE CVE VULNERABILITY TITLE RISK
2023-12-18 CVE-2023-6272 Improper Restriction of Excessive Authentication Attempts vulnerability in Thememylogin 2FA
The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.
network
low complexity
thememylogin CWE-307
critical
9.8