Known vulnerabilities in Two Factor (2FA) Authentication via Email
Enable one-click login with this WordPress Two-Factor Authentication (2FA) plugin, utilizing email for added security.
1Reported vulnerabilities
6.5Highest CVSS score
1.9.9Latest version
9,000+Active installs
What to do now
Update Two Factor (2FA) Authentication via Email to 1.9.9 or later.
1 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-13587 | Medium | 0.4% | 0 to 1.9.8 (inclusive) | 1.9.9 |
February 19, 2026 |