{
 "id": "WPSEC-2026-0526",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0526/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0526/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0526/index.md",
 "title": "WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Open Redirect via 'redirect_to' Parameter",
 "description": "The WP 2FA plugin for WordPress is vulnerable to Open Redirect in versions 2.5.0 up to, and including, 4.1.0. The plugin did not properly validate the 'redirect_to' parameter: the value was only passed through esc_url_raw() before the grace-period reminder and the REST-based two-factor login screen navigated the browser to it. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites right after they sign in, if they can successfully trick them into opening a crafted login link.",
 "plugin": {
  "slug": "wp-2fa",
  "name": "WP 2FA – Two-factor authentication for WordPress",
  "full_name": "WP 2FA – Two-factor authentication for WordPress",
  "wordpress_org": "https://wordpress.org/plugins/wp-2fa/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-2fa/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-2fa"
 },
 "type": "REDIRECT",
 "cwe": [
  "CWE-601"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.1,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.5.0",
    "from_inclusive": true,
    "to": "4.2.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.5.0 before 4.2.0"
  ]
 },
 "introduced_in": "2.5.0",
 "fixed_in": "4.2.0",
 "remediation": "Update to 4.2.0 or later.",
 "fix_released": "2026-10-06T12:19:29+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-06T19:48:17.074567+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0526/",
  "https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/",
  "https://wordpress.org/plugins/wp-2fa/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-2fa",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}