WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Bypass via Flywheel Direct Login Handling
- ID
- WPSEC-2026-0529
- Plugin
- WP 2FA – Two-factor authentication for WordPress (wp-2fa)
- Affected
- from 2.5.0 before 4.2.0
- Remediation
- Update to 4.2.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-287
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- WP 2FA – Two-factor authentication for WordPress on WPSec AttackSurface
- Fix released
- Published
Description
The WP 2FA plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions 2.5.0 up to, and including, 4.1.0. The Flywheel direct-login check in the login handler processed request-supplied values without validation or error handling, so malformed input could end the request with a fatal error after WordPress had already issued the authentication cookies and before the plugin withdrew them for the second-factor challenge. This makes it possible for unauthenticated attackers who know a user's password to obtain a logged-in session without completing the second factor on sites where the FW_DIRECT_LOGIN_SHARED_KEY constant is defined (Flywheel hosting).
References
- https://wpsec.com/vuln/WPSEC-2026-0529/
- https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/
- https://wordpress.org/plugins/wp-2fa/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS