Two Factor (2FA) Authentication via Email [two-factor-2fa-via-email] < 1.9.9
unknown
[en] The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 1.9.8. This is because the SS88_2FAVE::wp_login() method only enforces the 2FA requirement if the 'token' HTTP GET parameter is undefined, which makes it possible t...
- Affected:
- up to 1.9.9
- Fixed in:
- 1.9.9
- Disclosed:
- Feb 19, 2026
CVE-2025-13587 on NVD →
Two Factor (2FA) Authentication via Email <= 1.9.8 - Two-Factor Authentication Bypass via token
medium
The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 1.9.8. This is because the SS88_2FAVE::wp_login() method only enforces the 2FA requirement if the 'token' HTTP GET parameter is undefined, which makes it possible to byp...
- CVSS:
- 6.5
- Affected:
- up to 1.9.8
- Fixed in:
- 1.9.9
- Disclosed:
- Feb 18, 2026
CVE-2025-13587 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database