Known vulnerabilities in WebAuthn Provider for Two Factor
WebAuthn authentication provider for Two Factor plugin.
1Reported vulnerabilities
5.3Highest CVSS score
2.6.1Latest version
1,000+Active installs
What to do now
Update WebAuthn Provider for Two Factor to 2.5.6 or later.
1 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-11883 | Medium | 0.6% | 2.5.5 and earlier | 2.5.6 |
June 10, 2026 |