Product
CVE-2022-28601 allows an authenticated low-privileged user to bypass 2FA by overwriting a target account's associated phone number via the plugin's profile management endpoint.