Two Factor (2FA) Authentication via Email
Two Factor (2FA) Authentication via Email has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.
The most common weakness is Improper Input Validation, behind 1 of the records (100%).
The one issue recorded for Two Factor (2FA) Authentication via Email has a vendor fix available, so running the current release closes it.
All of these findings were reported by Ulyses Saicha. Two Factor (2FA) Authentication via Email is installed on roughly 9,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-13587Two Factor (2FA) Authentication via Email <= 1.9.8 - Two-Factor Authentication Bypass via token
Read the full analysisVulnerability Records

Two Factor (2FA) Authentication via Email
Author
Sully
A simple, lightweight, yet effective plugin to enable two factor (2FA) authentication via email. You can enable this on an individual user basis, for all administrators, editors, or all accounts with one line of code in your wp-config.php file. WordPress is the world’s most popular content management system (CMS), with over 40% of all websites running on it. As such, it has become a prime target for hackers looking to exploit vulnerabilities to gain unauthorized access to websites. One of the best ways to enhance the security of a WordPress site is to enable two-factor authentication (2FA) for administrators. Simply enable the plugin then edit a user account to enable 2FA for that individual user. Please make sure your WordPress website sends and receives emails correctly. The best way is to use a SMTP plugin. Check out our other plugins: 🎉 Media Library File Size ✨ Export Single Post Page 🙍♂️ View User Metadata 🔠 Enable Turnstile (Cloudflare) for Gravity Forms ⭐️⭐️⭐️⭐️⭐️ Gravity Forms to FreeScout
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C