WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Bypass via Brute Force

High 7.4 CWE-307Fixed in 4.2.0
ID
WPSEC-2026-0527
Plugin
WP 2FA – Two-factor authentication for WordPress (wp-2fa)
Affected
all versions before 4.2.0
Remediation
Update to 4.2.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness
CWE-307
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
WP 2FA – Two-factor authentication for WordPress on WPSec AttackSurface
Fix released
Published

Description

The WP 2FA plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versions up to, and including, 4.1.0 due to an insufficient limit on second-factor verification attempts. The failed-attempt counter was cleared once it reached its limit, and nothing prevented the user from being challenged again on the next password login. This makes it possible for unauthenticated attackers who know a user's password to make an unlimited number of guesses at the user's one-time code.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0