WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Cross-Site Request Forgery via REST API Nonce Check Bypass
- ID
- WPSEC-2026-0530
- Plugin
- WP 2FA – Two-factor authentication for WordPress (wp-2fa)
- Affected
- from 4.0.0 before 4.2.0
- Remediation
- Update to 4.2.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Weakness
- CWE-352
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- WP 2FA – Two-factor authentication for WordPress on WPSec AttackSurface
- Fix released
- Published
Description
The WP 2FA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.0 up to, and including, 4.1.0. The plugin exempted its login-validation REST route from WordPress's REST API cookie nonce check by matching the request URL rather than the route actually being served, so the exemption could also apply to other REST API routes. This makes it possible for unauthenticated attackers to perform actions available to a logged-in administrator through the REST API, such as creating or modifying user accounts, via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.
References
- https://wpsec.com/vuln/WPSEC-2026-0530/
- https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/
- https://wordpress.org/plugins/wp-2fa/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS