CVE-2026-15372
7.5 HIGHPublished 2026-08-05 · Updated 2026-08-05
AI risk analysis
- Summary
- The WP 2FA plugin before version 4.1.0 fails to validate the second authentication factor, allowing attackers with knowledge of a user's password to bypass two-factor authentication and gain full access to the account.
- Exploitability
- Exploitation is relatively easy for attackers who have obtained or guessed a user’s password, as no additional factors are validated during login.
- Blast radius
- If exploited, this flaw could lead to unauthorized access to user accounts, including administrator accounts, potentially compromising sensitive data and system integrity.
- Prioritized remediation
- Update the WP 2FA plugin to version 4.1.0 or later to ensure proper validation of second authentication factors.
auth-bypasswebwordpresssecurity
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-287
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.