Wordpress Alert: Two-factor authentication bypass in plugins
A third-party login route accepts a password without enforcing the site's second factor. A stolen password may become sufficient for account access.
What it looks like
A third-party login route accepts a password without enforcing the site's second factor.
Why it matters
A stolen password may become sufficient for account access.
What to check
Test every enabled login and API route against the configured second-factor policy.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP authentication guidance, WordPress REST authentication.
- Categories: WordPress
- Tags: #WordPress Security, #Authentication