Two-Factor Authentication Bypass in Email Authentication Plugin for WordPress
CVE-2025-13587
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 February 2026
What is CVE-2025-13587?
The Two Factor (2FA) Authentication via Email plugin for WordPress has a critical flaw that allows attackers to bypass two-factor authentication. The vulnerability arises from the SS88_2FAVE::wp_login() method, which improperly validates the 'token' HTTP GET parameter. If this parameter is defined, the 2FA requirement is not enforced, allowing an attacker to log in without providing valid authentication. This vulnerability affects versions up to and including 1.9.8, posing a significant risk to user accounts relying on this security feature.
Affected Version(s)
Two Factor (2FA) Authentication via Email 0 <= 1.9.8