WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Downgrade via 'provider' Parameter

High 7.4 CWE-287Fixed in 4.2.0
ID
WPSEC-2026-0528
Plugin
WP 2FA – Two-factor authentication for WordPress (wp-2fa)
Affected
all versions before 4.2.0
Remediation
Update to 4.2.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness
CWE-287
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
WP 2FA – Two-factor authentication for WordPress on WPSec AttackSurface
Fix released
Published

Description

The WP 2FA plugin for WordPress is vulnerable to a Two-Factor Authentication downgrade in all versions up to, and including, 4.1.0. The second-factor method used for the login challenge was taken from the request and was only checked against the methods enabled for the user's role, not against the method the user had configured. This makes it possible for unauthenticated attackers who know a user's password and can read the user's email to complete login with an emailed code instead of the user's configured authenticator app, when the email method is enabled for the user's role.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0