# WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Open Redirect via 'redirect_to' Parameter

- **ID:** WPSEC-2026-0526
- **Plugin:** WP 2FA – Two-factor authentication for WordPress (`wp-2fa`), https://wordpress.org/plugins/wp-2fa/
- **Affected versions:** from 2.5.0 before 4.2.0
- **Fixed in:** 4.2.0 (Update to 4.2.0 or later.)
- **Severity:** Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-601
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-2fa
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0526/

## Description

The WP 2FA plugin for WordPress is vulnerable to Open Redirect in versions 2.5.0 up to, and including, 4.1.0. The plugin did not properly validate the 'redirect_to' parameter: the value was only passed through esc_url_raw() before the grace-period reminder and the REST-based two-factor login screen navigated the browser to it. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites right after they sign in, if they can successfully trick them into opening a crafted login link.

## References

- https://wpsec.com/vuln/WPSEC-2026-0526/
- https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/
- https://wordpress.org/plugins/wp-2fa/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0526/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
