
IntegSec@integ_sec
CVE-2026-15372: WP 2FA Authentication Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04zcVqD0
000009
35 followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE-2026-15372: WP 2FA Authentication Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04zcVqD0