Vulnerabilities / WP 2FA – Two-factor authentication for WordPress / WPSEC-2026-0527
WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Bypass via Brute Force
High 7.4
CWE-307Fixed in 4.2.0
- ID
- WPSEC-2026-0527
- Plugin
- WP 2FA – Two-factor authentication for WordPress (wp-2fa)
- Affected
- all versions before 4.2.0
- Remediation
- Update to 4.2.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Weakness
- CWE-307
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- WP 2FA – Two-factor authentication for WordPress on WPSec AttackSurface
- Fix released
- Published
Description
The WP 2FA plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versions up to, and including, 4.1.0 due to an insufficient limit on second-factor verification attempts. The failed-attempt counter was cleared once it reached its limit, and nothing prevented the user from being challenged again on the next password login. This makes it possible for unauthenticated attackers who know a user's password to make an unlimited number of guesses at the user's one-time code.
References
- https://wpsec.com/vuln/WPSEC-2026-0527/
- https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/
- https://wordpress.org/plugins/wp-2fa/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS