WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Bypass via Flywheel Direct Login Handling

High 8.1 CWE-287Fixed in 4.2.0
ID
WPSEC-2026-0529
Plugin
WP 2FA – Two-factor authentication for WordPress (wp-2fa)
Affected
from 2.5.0 before 4.2.0
Remediation
Update to 4.2.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-287
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
WP 2FA – Two-factor authentication for WordPress on WPSec AttackSurface
Fix released
Published

Description

The WP 2FA plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions 2.5.0 up to, and including, 4.1.0. The Flywheel direct-login check in the login handler processed request-supplied values without validation or error handling, so malformed input could end the request with a fatal error after WordPress had already issued the authentication cookies and before the plugin withdrew them for the second-factor challenge. This makes it possible for unauthenticated attackers who know a user's password to obtain a logged-in session without completing the second factor on sites where the FW_DIRECT_LOGIN_SHARED_KEY constant is defined (Flywheel hosting).

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0