Impact
The WordPress plugin WebAuthn Provider for Two Factor fails to validate the second‑factor authentication response. An attacker who already knows a user’s password can submit a crafted request that causes the plugin to accept the response and log the user in without the second‑factor requirement. This results in the attacker gaining access to the account normally protected by two‑factor authentication.
Affected Systems
All releases of the WordPress plugin WebAuthn Provider for Two Factor prior to version 2.5.6 are affected. No other vendors or product variants are identified in the publicly available data.
Risk and Exploitability
The CVSS score of 7.2 indicates a high impact if the flaw is exploited. The EPSS score is < 1%, reflecting a low probability of exploitation. The vulnerability in the description, it is inferred that the attacker must already possess valid user credentials, so the risk is limited to situations where an attacker has compromised or guessed a password. Once credentials are available, the attacker can bypass the second‑factor check and gain full account control, potentially leading to further exploitation of the site. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment