Vulnerabilities / WP 2FA – Two-factor authentication for WordPress / WPSEC-2026-0526
WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Open Redirect via 'redirect_to' Parameter
Medium 6.1
CWE-601Fixed in 4.2.0
- ID
- WPSEC-2026-0526
- Plugin
- WP 2FA – Two-factor authentication for WordPress (wp-2fa)
- Affected
- from 2.5.0 before 4.2.0
- Remediation
- Update to 4.2.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Weakness
- CWE-601
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- WP 2FA – Two-factor authentication for WordPress on WPSec AttackSurface
- Fix released
- Published
Description
The WP 2FA plugin for WordPress is vulnerable to Open Redirect in versions 2.5.0 up to, and including, 4.1.0. The plugin did not properly validate the 'redirect_to' parameter: the value was only passed through esc_url_raw() before the grace-period reminder and the REST-based two-factor login screen navigated the browser to it. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites right after they sign in, if they can successfully trick them into opening a crafted login link.
References
- https://wpsec.com/vuln/WPSEC-2026-0526/
- https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/
- https://wordpress.org/plugins/wp-2fa/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS