WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Open Redirect via 'redirect_to' Parameter

Medium 6.1 CWE-601Fixed in 4.2.0
ID
WPSEC-2026-0526
Plugin
WP 2FA – Two-factor authentication for WordPress (wp-2fa)
Affected
from 2.5.0 before 4.2.0
Remediation
Update to 4.2.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-601
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
WP 2FA – Two-factor authentication for WordPress on WPSec AttackSurface
Fix released
Published

Description

The WP 2FA plugin for WordPress is vulnerable to Open Redirect in versions 2.5.0 up to, and including, 4.1.0. The plugin did not properly validate the 'redirect_to' parameter: the value was only passed through esc_url_raw() before the grace-period reminder and the REST-based two-factor login screen navigated the browser to it. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites right after they sign in, if they can successfully trick them into opening a crafted login link.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0