# WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Bypass via Flywheel Direct Login Handling

- **ID:** WPSEC-2026-0529
- **Plugin:** WP 2FA – Two-factor authentication for WordPress (`wp-2fa`), https://wordpress.org/plugins/wp-2fa/
- **Affected versions:** from 2.5.0 before 4.2.0
- **Fixed in:** 4.2.0 (Update to 4.2.0 or later.)
- **Severity:** High 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-287
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-2fa
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0529/

## Description

The WP 2FA plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions 2.5.0 up to, and including, 4.1.0. The Flywheel direct-login check in the login handler processed request-supplied values without validation or error handling, so malformed input could end the request with a fatal error after WordPress had already issued the authentication cookies and before the plugin withdrew them for the second-factor challenge. This makes it possible for unauthenticated attackers who know a user's password to obtain a logged-in session without completing the second factor on sites where the FW_DIRECT_LOGIN_SHARED_KEY constant is defined (Flywheel hosting).

## References

- https://wpsec.com/vuln/WPSEC-2026-0529/
- https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/
- https://wordpress.org/plugins/wp-2fa/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0529/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
