Two Factor (2FA) Authentication via Email

Two Factor (2FA) Authentication via Email has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.

The most common weakness is Improper Input Validation, behind 1 of the records (100%).

The one issue recorded for Two Factor (2FA) Authentication via Email has a vendor fix available, so running the current release closes it.

All of these findings were reported by Ulyses Saicha. Two Factor (2FA) Authentication via Email is installed on roughly 9,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Two Factor (2FA) Authentication via Email vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.5CVE-2025-13587

Two Factor (2FA) Authentication via Email <= 1.9.8 - Two-Factor Authentication Bypass via token

Read the full analysis

Vulnerability Records

1 records
Two Factor (2FA) Authentication via Email banner
Latestv1.9.9

Two Factor (2FA) Authentication via Email

Sully

Author

Sully

5.0(4)
100/100
Last Updated
2026-06-21 (3mo ago)
Active Installs
9,000+
Downloads
61,764
Requires WP
4.6+
Requires PHP
5.6+
Tested up to
WP 7.0.4
Created
2023-03-15 (4y ago)

A simple, lightweight, yet effective plugin to enable two factor (2FA) authentication via email. You can enable this on an individual user basis, for all administrators, editors, or all accounts with one line of code in your wp-config.php file. WordPress is the world’s most popular content management system (CMS), with over 40% of all websites running on it. As such, it has become a prime target for hackers looking to exploit vulnerabilities to gain unauthorized access to websites. One of the best ways to enhance the security of a WordPress site is to enable two-factor authentication (2FA) for administrators. Simply enable the plugin then edit a user account to enable 2FA for that individual user. Please make sure your WordPress website sends and receives emails correctly. The best way is to use a SMTP plugin. Check out our other plugins: 🎉 Media Library File Size ✨ Export Single Post Page 🙍‍♂️ View User Metadata 🔠 Enable Turnstile (Cloudflare) for Gravity Forms ⭐️⭐️⭐️⭐️⭐️ Gravity Forms to FreeScout

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C