Known Vulnerabilities for WP 2FA Two-factor Authentication For WordPress by Melapress
Listed below are 10 of the newest known vulnerabilities associated with "WP 2FA Two-factor Authentication For WordPress" by "Melapress".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-16578 json | The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not ... | Not Provided | 2026-08-08 | 2026-08-10 |
| CVE-2026-16055 json | The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authent... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-15372 json | The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported method... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-14291 json | The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-f... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-14204 json | The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-13690 json | The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login ha... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-12988 json | The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication ... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2026-12695 json | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-11883 json | The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authenticati... | Not Provided | 2026-07-01 | 2026-07-01 |
| CVE-2026-8903 json | The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver... | Not Provided | 2026-05-27 | 2026-05-27 |