Description
The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an attacker who already knows a user's password to bypass the two-factor authentication requirement by submitting a malformed request.
Published: 2026-07-01
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WebAuthn Provider for Two Factor plugin for WordPress fails to correctly validate the second‑factor authentication response, permitting an attacker who already has a user’s password to submit a malformed request that is accepted as a valid second factor. This flaw effectively bypasses the two‑factor protection, allowing credential‑only attackers to access accounts that rely on the plugin’s 2FA mechanism. The weakness essentially represents an authentication bypass vulnerability.

Affected Systems

WordPress sites that use the WebAuthn Provider for Two Factor plugin with a version prior to 2.5.6 are affected. No other vendors or product variants are reported to be impacted.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity, while the EPSS score of < 1% shows a low likelihood of exploitation in the wild. The vulnerability requires that the attacker already possess valid user credentials; with those credentials the attacker can submit a crafted second‑factor request and gain account control. Because it is not listed in the CISA KEV catalog, no coordinated exploitation campaign is known, but the potential to bypass 2FA makes it a serious threat for compromised accounts.

Generated by OpenCVE AI on August 5, 2026 at 02:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WebAuthn Provider for Two Factor plugin to version 2.5.6 or newer.
  • If an update cannot be applied immediately, remove or deactivate the plugin and employ an alternative two‑factor method such as TOTP or an authenticator app.
  • Deploy application‑level security controls, such as a web application firewall or rate‑limiting rules, to detect and block malformed authentication requests that aim to tamper with the second‑factor validation.

Generated by OpenCVE AI on August 5, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 04 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Fri, 31 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Mon, 27 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Fri, 17 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693

Wed, 15 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693

Sun, 12 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Fri, 10 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Thu, 09 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-305

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-305

Mon, 06 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-287

Sun, 05 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-287

Sun, 05 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE‑287

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE‑287

Fri, 03 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Thu, 02 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Thu, 02 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 01 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an attacker who already knows a user's password to bypass the two-factor authentication requirement by submitting a malformed request.
Title WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-01T10:16:55.102Z

Reserved: 2026-06-10T13:48:22.029Z

Link: CVE-2026-11883

cve-icon Vulnrichment

Updated: 2026-07-01T10:16:45.653Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T03:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation