{"id":"CVE-2026-15372","published":"2026-08-05T07:16:35.237","lastModified":"2026-08-05T16:16:50.750","description":"The WP 2FA  WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-287"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/a8d697c9-6de4-4a28-be9e-7d42abcb6c7e/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The WP 2FA plugin before version 4.1.0 fails to validate the second authentication factor, allowing attackers with knowledge of a user's password to bypass two-factor authentication and gain full access to the account.","exploitability":"Exploitation is relatively easy for attackers who have obtained or guessed a user’s password, as no additional factors are validated during login.","blast_radius":"If exploited, this flaw could lead to unauthorized access to user accounts, including administrator accounts, potentially compromising sensitive data and system integrity.","remediation":"Update the WP 2FA plugin to version 4.1.0 or later to ensure proper validation of second authentication factors.","tags":["auth-bypass","web","wordpress","security"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:57:02.158Z"}}