Description
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP 2FA plugin for WordPress fails to verify the second authentication factor when a supported method is chosen during login. An attacker who already knows a user's password can therefore bypass two‑factor protection and gain full access to the account, including administrator levels. This flaw enables credential misuse without additional privilege escalation, directly compromising confidentiality and integrity of the system.

Affected Systems

WordPress sites that use the WP 2FA plugin version 4.0.x or earlier. The affected vendor is the plugin author, commonly referred to as WP 2FA.

Risk and Exploitability

The vulnerability carries a high potential impact; an attacker only needs to know a valid password to subvert two‑factor authentication. Although no CVSS score is available in the public data, the lack of enforcement indicates a severe exploitability. The EPSS score is not reported, and the vulnerability has not been listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote, via the normal login page of the WordPress site, and does not require additional user interaction beyond supplying a password.

Generated by OpenCVE AI on August 5, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued upgrade to version 4.1.0 or newer, which corrects the second‑factor validation logic.
  • If the plugin configuration supports disabling the Passkeys provider or related feature, do so as an interim measure until the patch is deployed.
  • Review user accounts to ensure that no password‑only accounts are present for privileged roles; implement a strong password policy, including complexity requirements and regular rotation, to reduce the window of exploitation.

Generated by OpenCVE AI on August 5, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
Title WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T06:00:12.394Z

Reserved: 2026-07-10T08:35:15.325Z

Link: CVE-2026-15372

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T07:30:16Z

Weaknesses