Dueclic's vulnerability footprint centers on its WordPress two-factor authentication plugin leveraging Telegram, a focused utility for WordPress authentication workflows. The durable exposure pattern reflects authentication and session-handling weaknesses, including authorization bypass through user-controlled keys and insufficient cookie validation in security decisions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dueclic over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9687HIGH The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient validation of the user-contr | Oct 15, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-9820HIGH The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stor | Oct 15, 2024 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dueclic.
Media articles that mention a CVE ID that affects a product developed by Dueclic — matched by CVE ID, not by vendor name.