Vulnerability in WP 2FA – Two-factor authentication for WordPress — CVE-2026-62142
MediumSeverity
0.1%Estimated exploit probability
100,000+ sitesInstalls
4.2.0Fixed in
What to do now
Update WP 2FA – Two-factor authentication for WordPress to 4.2.0 or later.
Affected versions
- Everything up to and including 4.1.0
Affected: WP 2FA – Two-factor authentication for WordPress (plugin, wp-2fa)
What the vulnerability is
The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.