# WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Downgrade via 'provider' Parameter

- **ID:** WPSEC-2026-0528
- **Plugin:** WP 2FA – Two-factor authentication for WordPress (`wp-2fa`), https://wordpress.org/plugins/wp-2fa/
- **Affected versions:** all versions before 4.2.0
- **Fixed in:** 4.2.0 (Update to 4.2.0 or later.)
- **Severity:** High 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **Weakness:** CWE-287
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-2fa
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0528/

## Description

The WP 2FA plugin for WordPress is vulnerable to a Two-Factor Authentication downgrade in all versions up to, and including, 4.1.0. The second-factor method used for the login challenge was taken from the request and was only checked against the methods enabled for the user's role, not against the method the user had configured. This makes it possible for unauthenticated attackers who know a user's password and can read the user's email to complete login with an emailed code instead of the user's configured authenticator app, when the email method is enabled for the user's role.

## References

- https://wpsec.com/vuln/WPSEC-2026-0528/
- https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/
- https://wordpress.org/plugins/wp-2fa/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0528/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
