The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
History

Fri, 07 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp2fac
Wp2fac wp2fac
Vendors & Products Wordpress
Wordpress wordpress
Wp2fac
Wp2fac wp2fac

Wed, 05 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
Title WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-05T06:00:12.394Z

Updated: 2026-08-05T15:15:35.424Z

Reserved: 2026-07-10T08:35:15.325Z

Link: CVE-2026-15372

cve-icon Vulnrichment

Updated: 2026-08-05T15:15:31.374Z

cve-icon NVD

Status : Received

Published: 2026-08-05T07:16:35.237

Modified: 2026-08-05T16:16:50.750

Link: CVE-2026-15372

cve-icon Redhat

No data.