AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15372

HIGH · CVSS 7.5 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The WP 2FA WordPress plugin versions prior to 4.1.0 are vulnerable as they fail to validate the second authentication factor during login, enabling attackers with a user's password to bypass two-factor authentication. This flaw poses a significant risk, particularly for sites with administrator accounts, as it allows unauthorized access to sensitive functionalities. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.

CVE
CVE-2026-15372
Severity
HIGH
CVSS
7.5
EPSS
0.36%
WordPress

Original NVD Description

The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.