Description
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP 2FA plugin for WordPress fails to verify the second authentication factor when a supported method is chosen during login. An attacker who already knows a user’s password can therefore bypass two‑factor protection and gain full access to the account, including administrator levels. This flaw enables credential misuse without additional privilege escalation, directly compromising confidentiality and integrity of the system.

Affected Systems

WordPress sites that use the WP 2FA plugin version 4.0.x or earlier. The affected vendor is the plugin author, commonly referred to as WP 2FA.

Risk and Exploitability

The vulnerability carries a high potential impact; an attacker only needs to know a valid password to subvert two‑factor authentication. The CVSS score of 7.5 indicates a high severity level. The EPSS score is < 1%, indicating a low exploitation probability. The vulnerability has not been listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote, via the normal login page of the WordPress site, and does not require additional user interaction beyond supplying a password.

Generated by OpenCVE AI on August 5, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued upgrade to version 4.1.0 or newer, which corrects the second‑factor validation logic.
  • If the plugin configuration supports disabling the Passkeys provider or related feature, do so as an interim measure until the patch is deployed.
  • Review user accounts to ensure that no password‑only accounts are present for privileged roles; implement a strong password policy, including complexity requirements and regular rotation, to reduce the window of exploitation.

Generated by OpenCVE AI on August 5, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp2fac
Wp2fac wp2fac
Vendors & Products Wordpress
Wordpress wordpress
Wp2fac
Wp2fac wp2fac

Wed, 05 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
Title WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider
References

Subscriptions

Wordpress Wordpress
Wp2fac Wp2fac
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T15:15:35.424Z

Reserved: 2026-07-10T08:35:15.325Z

Link: CVE-2026-15372

cve-icon Vulnrichment

Updated: 2026-08-05T15:15:31.374Z

cve-icon NVD

Status : Deferred

Published: 2026-08-05T07:16:35.237

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-15372

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:30:11Z

Weaknesses