Impact
The WP 2FA WordPress plugin allows a user with valid credentials to reconfigure two‑factor authentication without proving ownership of the email address used in the setup. By providing an attacker‑controlled email, the plugin sends the verification code to that address and the attacker can complete the process, effectively taking over the account. This is a Missing Authorization flaw (CWE‑862).
Affected Systems
WordPress sites running the WP 2FA plugin older than 3.1.1.2 are vulnerable. The issue is confined to the plugin’s 2FA setup flow and does not require any specific WordPress core or theme version.
Risk and Exploitability
The CVSS score of 6.4 classifies the vulnerability as moderately serious. The EPSS score of less than 1% indicates that exploitation in the wild is unlikely at present, and the flaw is not listed in the CISA KEV catalog. An attacker would need to first obtain valid user credentials and then have the ability to receive the verification email. The likely attack vector is therefore credential‑based followed by email interception or redirection.
OpenCVE Enrichment