Known vulnerabilities in Two Factor Authentication
Secure WordPress login with Two Factor Authentication - supports WP, Woo + other login forms, HOTP, TOTP (Google Authenticator, Authy, etc.)
3Reported vulnerabilities
8.8Highest CVSS score
1.16.0Latest version
20,000+Active installs
What to do now
Update Two Factor Authentication to 2.1 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2018-20231 | High | 1.4% | Before 1.3.13 | 1.3.13 |
December 19, 2018 |
| CVE-2015-9355 | Medium | 1.0% | Before 1.1.10 | 1.1.10 |
August 28, 2019 |
| CVE-2022-4536 | Medium | 0.2% | Before 2.1 | 2.1 |
August 31, 2024 |