WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Cross-Site Request Forgery via REST API Nonce Check Bypass

High 8.8 CWE-352Fixed in 4.2.0
ID
WPSEC-2026-0530
Plugin
WP 2FA – Two-factor authentication for WordPress (wp-2fa)
Affected
from 4.0.0 before 4.2.0
Remediation
Update to 4.2.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness
CWE-352
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
WP 2FA – Two-factor authentication for WordPress on WPSec AttackSurface
Fix released
Published

Description

The WP 2FA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.0 up to, and including, 4.1.0. The plugin exempted its login-validation REST route from WordPress's REST API cookie nonce check by matching the request URL rather than the route actually being served, so the exemption could also apply to other REST API routes. This makes it possible for unauthenticated attackers to perform actions available to a logged-in administrator through the REST API, such as creating or modifying user accounts, via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0