← Back to search

CVE-2026-15372

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The WP 2FA plugin before version 4.1.0 fails to validate the second authentication factor, allowing attackers with knowledge of a user's password to bypass two-factor authentication and gain full access to the account.
Exploitability
Exploitation is relatively easy for attackers who have obtained or guessed a user’s password, as no additional factors are validated during login.
Blast radius
If exploited, this flaw could lead to unauthorized access to user accounts, including administrator accounts, potentially compromising sensitive data and system integrity.
Prioritized remediation
Update the WP 2FA plugin to version 4.1.0 or later to ensure proper validation of second authentication factors.
auth-bypasswebwordpresssecurity

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-287

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.