Description
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
Published: 2026-07-29
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The UsersWP WordPress plugin before version 1.2.67 has an internal flaw where the two‑factor login handler fails to validate the chosen authentication provider. An attacker who already knows a user’s normal credentials can exploit this omission to skip the second factor and create a legitimate login session. This vulnerability is a type of authentication bypass (CWE‑287) that directly undermines user identity protection and could lead to unauthorized access to sensitive data or site administration if combined with other privileges.

Affected Systems

The affected environment consists of WordPress sites that have the UsersWP plugin installed, any version prior to 1.2.67. The issue is limited to the plugin’s two‑factor authentication component and does not affect WordPress core or other plugins unless they share authentication flows.

Risk and Exploitability

The CVSS score of 7.4 indicates high potential impact if exploited, and the EPSS score of less than 1% suggests that the vulnerability is unlikely to be widely attacked at present. It is not listed in CISA’s KEV catalog, indicating no publicly known exploit. An attacker would need to know the victim’s credentials first; once those are known, they can simply request a two‑factor login and the plugin will accept the request without verifying the provider. The attack can be performed over the public HTTPS interface of the site and requires no special privileges beyond credential compromise.

Generated by OpenCVE AI on August 3, 2026 at 13:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the UsersWP plugin to version 1.2.67 or later, which includes validation of the selected authentication provider
  • Confirm that the two‑factor authentication configuration on the site is properly enabled and that the provider selection cannot be overridden via URL or cookie manipulation
  • If an immediate upgrade is not possible, disable the UsersWP plugin or block access to its two‑factor endpoint until a patch is applied

Generated by OpenCVE AI on August 3, 2026 at 13:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Userswp
Userswp userswp
Wordpress
Wordpress wordpress
Vendors & Products Userswp
Userswp userswp
Wordpress
Wordpress wordpress

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
Title UsersWP < 1.2.67 - Two-Factor Authentication Bypass
References

Subscriptions

Userswp Userswp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-29T12:38:26.923Z

Reserved: 2026-06-29T11:08:13.255Z

Link: CVE-2026-13690

cve-icon Vulnrichment

Updated: 2026-07-29T12:38:10.523Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T07:16:41.460

Modified: 2026-07-30T14:16:31.463

Link: CVE-2026-13690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:00:07Z

Weaknesses