{
 "id": "WPSEC-2026-0528",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0528/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0528/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0528/index.md",
 "title": "WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Downgrade via 'provider' Parameter",
 "description": "The WP 2FA plugin for WordPress is vulnerable to a Two-Factor Authentication downgrade in all versions up to, and including, 4.1.0. The second-factor method used for the login challenge was taken from the request and was only checked against the methods enabled for the user's role, not against the method the user had configured. This makes it possible for unauthenticated attackers who know a user's password and can read the user's email to complete login with an emailed code instead of the user's configured authenticator app, when the email method is enabled for the user's role.",
 "plugin": {
  "slug": "wp-2fa",
  "name": "WP 2FA – Two-factor authentication for WordPress",
  "full_name": "WP 2FA – Two-factor authentication for WordPress",
  "wordpress_org": "https://wordpress.org/plugins/wp-2fa/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-2fa/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-2fa"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-287"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.4,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "4.2.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 4.2.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "4.2.0",
 "remediation": "Update to 4.2.0 or later.",
 "fix_released": "2026-10-06T12:19:29+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-06T19:48:17.074567+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0528/",
  "https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/",
  "https://wordpress.org/plugins/wp-2fa/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-2fa",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}