Impact
The WP 2FA plugin for WordPress fails to verify the second authentication factor when a supported method is chosen during login. An attacker who already knows a user's password can therefore bypass two‑factor protection and gain full access to the account, including administrator levels. This flaw enables credential misuse without additional privilege escalation, directly compromising confidentiality and integrity of the system.
Affected Systems
WordPress sites that use the WP 2FA plugin version 4.0.x or earlier. The affected vendor is the plugin author, commonly referred to as WP 2FA.
Risk and Exploitability
The vulnerability carries a high potential impact; an attacker only needs to know a valid password to subvert two‑factor authentication. Although no CVSS score is available in the public data, the lack of enforcement indicates a severe exploitability. The EPSS score is not reported, and the vulnerability has not been listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote, via the normal login page of the WordPress site, and does not require additional user interaction beyond supplying a password.
OpenCVE Enrichment