{"error":0,"message":null,"data":{"name":"WP 2FA &#8211; Two-factor authentication for WordPress","plugin":"wp-2fa","link":"https:\/\/wordpress.org\/plugins\/wp-2fa\/","latest":"1786438260","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"2d1d87d0787c3dedfeaa572c80a468dcb0453111047dafc860a6cac7d25e4991","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"187b426eea97d75fad4202e60fc8c41a3407977f","name":"WordPress WP 2FA plugin <= 2.1.0 - Arbitrary 2FA Disabling via Insecure Direct Object References (IDOR) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-2fa\/vulnerability\/wordpress-wp-2fa-plugin-2-1-0-arbitrary-2fa-disabling-via-insecure-direct-object-references-idor-vulnerability","description":"Arbitrary 2FA Disabling via Insecure Direct Object References (IDOR) vulnerability discovered by Maycon Vitali in WordPress WP 2FA plugin (versions <= 2.1.0).","date":"2022-04-29"}],"impact":[]},{"uuid":"a9c66164a76a08b74d8b62c456592eceec37b385e2297dd419a415819555c2cd","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-1527","name":"CVE-2022-1527","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-1527","description":"[en] The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting","date":"2022-05-30"},{"id":"b7a1badeb6ec4c6b48cd302f6909fd9815a45d90","name":"WP 2FA \u2013 Two-factor authentication for WordPress <= 2.2.0 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-2fa\/wp-2fa-two-factor-authentication-for-wordpress-220-reflected-cross-site-scripting","description":"The WP 2FA WordPress plugin before 2.2.1 does not sanitize and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue.","date":"2022-05-06"},{"id":"cda5bb5d642afea513ead6e59ab50f3d05c78552","name":"WordPress  WP 2FA Plugin  <= 2.2.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-2fa\/vulnerability\/wordpress-wp-2fa-plugin-2-2-0-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress WP 2FA plugin to the latest available version (at least 2.2.1).\nUtkarsh Agrawal discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP 2FA Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 2.2.1.","date":"2023-05-06"},{"id":"0260d5c0-52a9-44ce-b7be-aff642056d16","name":"WP 2FA &lt; 2.2.1 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/0260d5c0-52a9-44ce-b7be-aff642056d16","description":"The plugin does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"7937eb5559b91e59b15678d8d1606841c0ea5f6502275125d839c78eca1e29cb","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2891","name":"CVE-2022-2891","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2891","description":"[en] The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.","date":"2022-10-10"},{"id":"3eb836746e89e7a2ab06bf80a08942bedba6edc8","name":"WP 2FA <= 2.2.1 - Time-Based TOTP attack to Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-2fa\/wp-2fa-221-time-based-totp-attack-to-sensitive-information-exposure","description":"The WP 2FA plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.2.1 due to the use of a linear-time comparison operator when comparing token hashes. This allows an attacker to gain information about authentication tokens by observing small time differences in server response times. This is a vulnerability that is generally not realistically exploitable over the internet due to other factors that will have a greater influence on response times.","date":"2022-09-14"},{"id":"ce6491ca2c611552defde54d13875698acab1647","name":"WordPress  WP 2FA Plugin  <= 2.2.1 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-2fa\/vulnerability\/wordpress-wp-2fa-plugin-2-2-1-time-based-side-channel-attack-vulnerability","description":"Update the WordPress WP 2FA plugin to the latest available version (at least 2.3.0).\nCalvin Alkan discovered and reported this Sensitive Data Exposure vulnerability in WordPress WP 2FA Plugin.  This vulnerability has been fixed in version 2.3.0.","date":"2023-09-14"},{"id":"301b3dce-2584-46ec-92ed-1c0626522120","name":"WP 2FA &lt; 2.3.0 - Time-Based Side-Channel Attack","link":"https:\/\/wpscan.com\/vulnerability\/301b3dce-2584-46ec-92ed-1c0626522120","description":"The plugin uses comparison operators that don&#039;t mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"5.9","severity":"m","exploitable":"2.2","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"5.9","severity":"medium","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.2","impact":"3.6"},"cwe":[{"cwe":"CWE-203","name":"Observable Discrepancy","description":"The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not."}]}},{"uuid":"32d8500c2603905c9e039c2316fef86ae60c324705597623e105cb71ed635a1b","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bec9d356f96855457ab85382efeb5544dd0d3d43","name":"WordPress WP 2FA Plugin <= 2.2.0 is vulnerable to Broken Authentication","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-2fa\/vulnerability\/wordpress-wp2fa-plugin-2-2-0-broken-authentication-vulnerability","description":"Update the WordPress WP 2FA plugin to the latest available version (at least 2.2.1).\nCalvin Alkan discovered and reported this Broken Authentication vulnerability in WordPress WP 2FA Plugin. This can be abused by a malicious actor to perform action which normally should only be able to be executed by higher privileged users. These actions might allow the malicious actor to gain admin access to the website. This vulnerability has been fixed in version 2.2.1.","date":null}],"impact":[]},{"uuid":"f89e295fa74eeabccb54796040ba9d3d28588eb0b569798bcc38f220a1de7558","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-44595","name":"CVE-2022-44595","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-44595","description":"[en] Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n\/a through 2.2.0.","date":"2024-03-21"},{"id":"bc62a4f6b3f7311e3e8edd89e16c848b5bbb1bc7","name":"WP 2FA \u2013 Two-factor authentication for WordPress <= 2.2.0 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-2fa\/wp-2fa-two-factor-authentication-for-wordpress-220-missing-authorization","description":"The WP 2FA plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the login_form_validate_2fa function in versions up to, and including, 2.2.0. This makes it possible for authenticated attackers to receive a 2fa login code even if the provider is not enabled for that user.","date":"2022-12-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"1914dde1f214b888d6f59331fd2aa95427b54faea13bacfb74eb340506b73aee","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5635beb1548489ed304264d601894dab40cb9697","name":"WP 2FA \u2013 Two-factor authentication for WordPress <= 2.1.0 - Insecure Direct Object Reference","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-2fa\/wp-2fa-two-factor-authentication-for-wordpress-210-insecure-direct-object-reference","description":"The WP 2FA \u2013 Two-factor authentication for WordPress plugin for WordPress make it possible for attackers to disable other user's 2FA settings in versions up to, and including, 2.1.0.","date":"2022-04-13"}],"impact":[]},{"uuid":"103524bac73335e9f09dbc139d0fb0aa9a71f184e3f84c0d9385768f4515088b","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5f7aa2b7-28f9-4ddd-9ec8-b370e545bd1b","name":"WP 2FA &lt; 2.2.0 - Arbitrary 2FA Disabling via IDOR","link":"https:\/\/wpscan.com\/vulnerability\/5f7aa2b7-28f9-4ddd-9ec8-b370e545bd1b","description":"The plugin does not properly check for authorisation when disabling 2FA, allowing users to disable the protection of other users via an IDOR attack","date":null}],"impact":[]},{"uuid":"cec1a655bcbf32a484a4c311e2b1415af6461151a812b72b000e71d911584457","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6506","name":"CVE-2023-6506","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6506","description":"[en] The WP 2FA \u2013 Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.0 via the send_backup_codes_email due to missing validation on a user controlled key. This makes it possible for subscriber-level attackers to email arbitrary users on the site.","date":"2024-01-11"},{"id":"6f4a5a12c45585b5f2a1589e6dc1143a2b02bebe","name":"WP 2FA <= 2.5.0 - Insecure Direct Object Reference to Arbitrary Email Sending","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-2fa\/two-factor-authentication-for-wordpress-250-insecure-direct-object-reference-to-arbitrary-email-sending","description":"The WP 2FA \u2013 Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.0 via the send_backup_codes_email due to missing validation on a user controlled key. This makes it possible for subscriber-level attackers to email arbitrary users on the site.","date":"2024-01-02"},{"id":"9971ef65e2cfada1788df3c5211d73f004e0fe48","name":"WordPress  WP 2FA Plugin  <= 2.5.0 is vulnerable to Insecure Direct Object References (IDOR)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-2fa\/vulnerability\/wordpress-wp-2fa-plugin-2-5-0-insecure-direct-object-reference-to-arbitrary-email-sending-vulnerability","description":"Update the WordPress WP 2FA plugin to the latest available version (at least 2.6.0).\nUlyses Saicha discovered and reported this Insecure Direct Object References (IDOR) vulnerability in WordPress WP 2FA Plugin. An insecure direct object reference vulnerability could allow a malicious actor to bypass authorization, authentication, access sensitive files\/folders or interact with the database.  This vulnerability has been fixed in version 2.6.0.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-03"},{"id":"f5515518-4cdb-4a9b-a88d-b450a6755038","name":"WP 2FA &lt; 2.6.0 - Subscriber+ Arbitrary Email Sending","link":"https:\/\/wpscan.com\/vulnerability\/f5515518-4cdb-4a9b-a88d-b450a6755038","description":"The plugin is vulnerable to Insecure Direct Object Reference via the send_backup_codes_email due to missing validation on a user controlled key. This makes it possible for subscriber-level attackers to email arbitrary users on the site.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."},{"cwe":"CWE-732","name":"Incorrect Permission Assignment for Critical Resource","description":"The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"adcdba1fce78110128e835abb06fc3d9a4749a376e49700440a37f4c05b78213","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6520","name":"CVE-2023-6520","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6520","description":"[en] The WP 2FA \u2013 Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.0. This is due to missing or incorrect nonce validation on the send_backup_codes_email function. This makes it possible for unauthenticated attackers to send emails with arbitrary content to registered users via a forged request granted they can trick a site administrator or other registered user into performing an action such as clicking on a link. While a nonce check is present, it is only executed if a nonce is set. By omitting a nonce from the request, the check can be bypassed.","date":"2024-01-11"},{"id":"03bbbdef2cab0640b72dc71af6b6856130f3edfe","name":"WP 2FA \u2013 Two-factor authentication for WordPress <= 2.5.0 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-2fa\/wp-2fa-two-factor-authentication-for-wordpress-250-cross-site-request-forgery","description":"The WP 2FA \u2013 Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.0. This is due to missing or incorrect nonce validation on the send_backup_codes_email function. This makes it possible for unauthenticated attackers to send emails with arbitrary content to registered users via a forged request granted they can trick a site administrator or other registered user into performing an action such as clicking on a link. While a nonce check is present, it is only executed if a nonce is set. By omitting a nonce from the request, the check can be bypassed.","date":"2024-01-02"},{"id":"34b5229c44f6d541112b29233337d6ef0580491e","name":"WordPress  WP 2FA Plugin  <= 2.5.0 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-2fa\/vulnerability\/wordpress-wp-2fa-plugin-2-5-0-cross-site-request-forgery-vulnerability","description":"Update the WordPress WP 2FA plugin to the latest available version (at least 2.6.0).\nUlyses Saicha discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WP 2FA Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 2.6.0.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-03"},{"id":"d5e842a4-16b7-430f-a018-176f94422b66","name":"WP 2FA &lt; 2.6.0 - Arbitrary Email Sending via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/d5e842a4-16b7-430f-a018-176f94422b66","description":"The plugin has a flawed CSRF check when sending emails to registered users, which could allow attackers to make logged in admins perform such action via a CSRF attack","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"70dc1a93bac891d189a34e188a9eafe91c97501935e9fc366887f65680a9222c","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-32568","name":"CVE-2024-32568","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-32568","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP 2FA wp-2fa.This issue affects WP 2FA: from n\/a through <= 2.6.2.","date":"2024-04-18"},{"id":"38821d95c6358381aa0bfd994aec415756b9a8d7","name":"WordPress WP 2FA Plugin <= 2.6.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-2fa\/vulnerability\/wordpress-wp-2fa-plugin-2-6-2-reflected-cross-site-scripting-xss-vulnerability","description":"<p>WordPress WP 2FA Plugin <= 2.6.2 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: WP 2FA<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-2fa\/#developers<\/p><p>Affected Version <= 2.6.2<\/p><p>Fixed in version 2.6.3 <\/p>","date":"2024-04-16"},{"id":"18f7967bdea48cd20a847ed8dfd0a8faa4ac6b9f","name":"WP 2FA \u2013 Two-factor authentication for WordPress <= 2.6.2 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-2fa\/wp-2fa-two-factor-authentication-for-wordpress-262-reflected-cross-site-scripting","description":"The WP 2FA \u2013 Two-factor authentication for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-04-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ab843de3eacddeb4c3748010e9b7615575409ff49f73aec34c0632921b32e8a5","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 2.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-44587","name":"CVE-2022-44587","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-44587","description":"[en] Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP 2FA: from n\/a through 2.6.3.","date":"2024-06-21"},{"id":"1c79ac2678a7b92b4282f8a7e1f3ddf968b49501","name":"WordPress WP 2FA Plugin <= 2.6.3 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-2fa\/vulnerability\/wordpress-wp-2fa-plugin-2-6-3-sensitive-data-exposure-via-log-file-vulnerability","description":"<p>WordPress WP 2FA Plugin <= 2.6.3 is vulnerable to Sensitive Data Exposure<\/p><p>Software: WP 2FA<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-2fa\/#developers<\/p><p>Affected Version <= 2.6.3<\/p><p>Fixed in version 2.6.4 <\/p>","date":"2024-06-20"},{"id":"ad91101e82177be91887f549c0cf23b0e98e7439","name":"WP 2FA <= 2.6.3 - Unauthenticated Information Exposure via Log File","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-2fa\/wp-2fa-263-unauthenticated-information-exposure-via-log-file","description":"The WP 2FA \u2013 Two-factor authentication for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.3 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.","date":"2024-06-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-532","name":"Insertion of Sensitive Information into Log File","description":"The product writes sensitive information to a log file."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c3bdcc94c2458c0c0d5da40c773104138212eda88eef15c41dcac6f5dac2e742","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 3.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-12628","name":"CVE-2025-12628","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12628","description":"[en] The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them","date":"2025-11-24"},{"id":"100a23710e4f9d32cb9f4d7a803a1b2b8a84cae1","name":"WP 2FA \u2013 Two-factor authentication for WordPress <= 2.9.3 - 2-Factor Authentication Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-2fa\/wp-2fa-two-factor-authentication-for-wordpress-293-2-factor-authentication-bypass","description":"The WP 2FA \u2013 Two-factor authentication for WordPress plugin for WordPress is vulnerable to 2FA bypass in all versions up to, and including, 2.9.3. This makes it possible for unauthenticated attackers to bypass 2FA protection. Please note Wordfence does not consider this a security vulnerability and previously rejected assigning a CVE ID to this issue. This is being included for informational purposes.","date":"2025-11-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"6.3","severity":"m","exploitable":"2.8","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"6.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"3.4"},"cwe":[{"cwe":"CWE-331","name":"Insufficient Entropy","description":"The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fd8d482050db59d70ee564b86f30a983d07acd529f4ca64a5b275223b2824798","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 3.1.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12988","name":"CVE-2026-12988","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12988","description":"[en] The WP 2FA  WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account.","date":"2026-07-14"},{"id":"97ab65e0f4a4750b0a174c433d16f6ccc515ca2f","name":"WP 2FA <= 3.1.1.1 - Authenticated (Subscriber+) Account Takeover","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-2fa\/wp-2fa-3111-authenticated-subscriber-account-takeover","description":"The WP 2FA \u2013 Two-factor authentication for WordPress plugin for WordPress is vulnerable to accoutn takeover in all versions up to, and including, 3.1.1.1. This is due to the plugin not properly verifying an email during 2FA enrollment. This makes it possible for authenticated attackers, with subscriber-level access and above, to complete verification for other users gaining access to their account.","date":"2026-06-23"}],"impact":{"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6dd9dd1b5a0ad7b862ff1b54cec990bf1325832395e9ce34bc63c24de1687308","name":"WP 2FA &#8211; Two-factor authentication for WordPress [wp-2fa] < 4.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15372","name":"CVE-2026-15372","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15372","description":"[en] The WP 2FA  WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.","date":"2026-08-05"}],"impact":{"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1785997282"}