# WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Bypass via Brute Force

- **ID:** WPSEC-2026-0527
- **Plugin:** WP 2FA – Two-factor authentication for WordPress (`wp-2fa`), https://wordpress.org/plugins/wp-2fa/
- **Affected versions:** all versions before 4.2.0
- **Fixed in:** 4.2.0 (Update to 4.2.0 or later.)
- **Severity:** High 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **Weakness:** CWE-307
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-2fa
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0527/

## Description

The WP 2FA plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versions up to, and including, 4.1.0 due to an insufficient limit on second-factor verification attempts. The failed-attempt counter was cleared once it reached its limit, and nothing prevented the user from being challenged again on the next password login. This makes it possible for unauthenticated attackers who know a user's password to make an unlimited number of guesses at the user's one-time code.

## References

- https://wpsec.com/vuln/WPSEC-2026-0527/
- https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/
- https://wordpress.org/plugins/wp-2fa/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0527/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
