WordPress Plugin Vulnerabilities

UsersWP < 1.2.67 - Two-Factor Authentication Bypass

Description

The plugin does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.

Proof of Concept

Affects Plugins

Fixed in 1.2.67

References

Classification

Miscellaneous

Original Researcher
dc11
Submitter
dc11
Verified
Yes

Timeline

Publicly Published
2026-07-08 (about 18 days ago)
Added
2026-07-08 (about 18 days ago)
Last Updated
2026-07-08 (about 18 days ago)

Other