WebAuthn Provider for Two Factor

WebAuthn Provider for Two Factor has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Improper Authentication, behind 1 of the records (100%).

The one issue recorded for WebAuthn Provider for Two Factor has a vendor fix available, so running the current release closes it.

All of these findings were reported by Volodymyr Kolesnykov. WebAuthn Provider for Two Factor is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WebAuthn Provider for Two Factor vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2026-11883

WebAuthn Provider for Two Factor <= 2.5.5 - Two-Factor Authentication Bypass

Read the full analysis

Vulnerability Records

1 records
WebAuthn Provider for Two Factor banner
Latestv2.6.1

WebAuthn Provider for Two Factor

Volodymyr Kolesnykov

Author

Volodymyr Kolesnykov

4.6(11)
92/100
Last Updated
2026-03-12 (5mo ago)
Active Installs
1,000+
Downloads
40,124
Requires WP
6.0+
Requires PHP
8.1+
Tested up to
WP 6.9.7
Created
2022-01-28 (5y ago)

This plugin adds WebAuthn and passkey support to the Two Factor plugin, providing a modern, secure authentication method. Features: Support for WebAuthn and passkeys (Windows Hello, Touch ID, YubiKeys, etc.) Backward compatibility with previously registered U2F security keys User-friendly settings and seamless authentication experience Customizable error logging and behavior via action hooks Works with the Two Factor plugin for flexible 2FA authentication The plugin enables users to register and use hardware security keys and platform authenticators for stronger protection against password-based attacks and phishing. Notes: please use GitHub issues to report bugs; the full source code with all development files is available on GitHub.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C