PT-2026-43532 · Youtag+1 · Two-Factor Authentication+1

·

CVE-2026-8903

·

Published

2026-05-26

·

Updated

2026-06-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Two-factor authentication (formerly IP Vault) plugin for WordPress versions prior to 2.2
Description This issue involves Cross-Site Request Forgery, a flaw where an attacker tricks a victim into performing actions they did not intend to do. The problem occurs due to missing or incorrect nonce validation in the ipv save changes() function. Unauthenticated attackers can exploit this to modify firewall and two-factor authentication settings, such as the operating mode, request include/exclude rules, authentication slug, and log retention period, which could lead to the complete disabling of protection.
Recommendations Update the plugin to a version newer than 2.1. As a temporary mitigation, restrict access to the ipv save changes() function.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8903

Affected Products

Two-Factor Authentication
Ip-Vault-Wp-Firewall