PT-2026-67973 · WordPress · Wp 2Fa

·

CVE-2026-15372

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP 2FA versions prior to 4.1.0
Description The plugin fails to validate the second authentication factor during the login process when a supported method is selected. This allows an attacker who possesses a user's password to bypass the two-factor authentication mechanism and gain full access to the account, including those with administrator privileges.
Recommendations Update to version 4.1.0 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15372

Affected Products

Wp 2Fa