Two-Factor Authentication Bypass in Email Authentication Plugin for WordPress
CVE-2025-13587

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 February 2026

What is CVE-2025-13587?

The Two Factor (2FA) Authentication via Email plugin for WordPress has a critical flaw that allows attackers to bypass two-factor authentication. The vulnerability arises from the SS88_2FAVE::wp_login() method, which improperly validates the 'token' HTTP GET parameter. If this parameter is defined, the 2FA requirement is not enforced, allowing an attacker to log in without providing valid authentication. This vulnerability affects versions up to and including 1.9.8, posing a significant risk to user accounts relying on this security feature.

Affected Version(s)

Two Factor (2FA) Authentication via Email 0 <= 1.9.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ulyses Saicha
.