Impact
The WebAuthn Provider for Two Factor plugin for WordPress fails to correctly validate the second‑factor authentication response, permitting an attacker who already has a user’s password to submit a malformed request that is accepted as a valid second factor. This flaw effectively bypasses the two‑factor protection, allowing credential‑only attackers to access accounts that rely on the plugin’s 2FA mechanism. The weakness essentially represents an authentication bypass vulnerability.
Affected Systems
WordPress sites that use the WebAuthn Provider for Two Factor plugin with a version prior to 2.5.6 are affected. No other vendors or product variants are reported to be impacted.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the EPSS score of < 1% shows a low likelihood of exploitation in the wild. The vulnerability requires that the attacker already possess valid user credentials; with those credentials the attacker can submit a crafted second‑factor request and gain account control. Because it is not listed in the CISA KEV catalog, no coordinated exploitation campaign is known, but the potential to bypass 2FA makes it a serious threat for compromised accounts.
OpenCVE Enrichment