# WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Cross-Site Request Forgery via REST API Nonce Check Bypass

- **ID:** WPSEC-2026-0530
- **Plugin:** WP 2FA – Two-factor authentication for WordPress (`wp-2fa`), https://wordpress.org/plugins/wp-2fa/
- **Affected versions:** from 4.0.0 before 4.2.0
- **Fixed in:** 4.2.0 (Update to 4.2.0 or later.)
- **Severity:** High 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-352
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-2fa
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0530/

## Description

The WP 2FA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.0 up to, and including, 4.1.0. The plugin exempted its login-validation REST route from WordPress's REST API cookie nonce check by matching the request URL rather than the route actually being served, so the exemption could also apply to other REST API routes. This makes it possible for unauthenticated attackers to perform actions available to a logged-in administrator through the REST API, such as creating or modifying user accounts, via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

## References

- https://wpsec.com/vuln/WPSEC-2026-0530/
- https://plugins.svn.wordpress.org/wp-2fa/tags/4.2.0/
- https://wordpress.org/plugins/wp-2fa/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0530/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
