Description
The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes.
Problem types
CWE-287 Improper Authentication
Product status
1.5
Timeline
2025-08-19: | Vendor Notified |
2025-08-27: | Disclosed |
Credits
Kenneth Dunn
References
www.wordfence.com/...-296d-4f33-9fe0-964c0c0a9652?source=cve
wordpress.org/plugins/rccp-free/
plugins.trac.wordpress.org/...ree/tags/1.6.8/ringcentral.php
plugins.trac.wordpress.org/changeset/3349361/