{
 "id": "WPSEC-2026-0527",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0527/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0527/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0527/index.md",
 "title": "WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Bypass via Brute Force",
 "description": "The WP 2FA plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versions up to, and including, 4.1.0 due to an insufficient limit on second-factor verification attempts. The failed-attempt counter was cleared once it reached its limit, and nothing prevented the user from being challenged again on the next password login. This makes it possible for unauthenticated attackers who know a user's password to make an unlimited number of guesses at the user's one-time code.",
 "plugin": {
  "slug": "wp-2fa",
  "name": "WP 2FA – Two-factor authentication for WordPress",
  "full_name": "WP 2FA – Two-factor authentication for WordPress",
  "wordpress_org": "https://wordpress.org/plugins/wp-2fa/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-2fa/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-2fa"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-307"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.4,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "4.2.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 4.2.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "4.2.0",
 "remediation": "Update to 4.2.0 or later.",
 "fix_released": "2026-10-06T12:19:29+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-06T19:48:17.074567+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0527/",
  "https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/",
  "https://wordpress.org/plugins/wp-2fa/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-2fa",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}