Vulnerabilities / WP 2FA – Two-factor authentication for WordPress
WP 2FA – Two-factor authentication for WordPress vulnerabilities
Advisories WPSec published for WP 2FA – Two-factor authentication for WordPress. Other sources may list more. Its attack surface: WP 2FA – Two-factor authentication for WordPress on WPSec AttackSurface.
| Published | ID | Vulnerability | Severity | Fixed in |
|---|---|---|---|---|
| 2026-10-07 | WPSEC-2026-0530 | WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Cross-Site Request Forgery via REST API Nonce Check Bypass | High 8.8 | 4.2.0 |
| 2026-10-07 | WPSEC-2026-0529 | WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Bypass via Flywheel Direct Login Handling | High 8.1 | 4.2.0 |
| 2026-10-07 | WPSEC-2026-0528 | WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Downgrade via 'provider' Parameter | High 7.4 | 4.2.0 |
| 2026-10-07 | WPSEC-2026-0527 | WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Two-Factor Authentication Bypass via Brute Force | High 7.4 | 4.2.0 |
| 2026-10-07 | WPSEC-2026-0526 | WP 2FA – Two-factor authentication for WordPress <= 4.1.0 - Unauthenticated Open Redirect via 'redirect_to' Parameter | Medium 6.1 | 4.2.0 |
License: CC BY 4.0