CVE-2026-15372 PUBLISHED

WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider

Assigner: WPScan
Reserved: 10.07.2026 Published: 05.08.2026 Updated: 05.08.2026

The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.

Product Status

Vendor Unknown
Product WP 2FA
Versions Default: unaffected
  • affected from 0 to 4.1.0 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE