Bypassing Two-Factor Authentication in UsersWP WordPress Plugin
CVE-2026-13690
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-13690?
The UsersWP WordPress plugin, prior to version 1.2.67, is susceptible to an authentication bypass vulnerability in its two-factor login handler. This issue arises due to a failure to validate the selected authentication provider, enabling attackers who have obtained a user's credentials to circumvent the second factor of authentication, leading to unauthorized access to user accounts.
Affected Version(s)
UsersWP 0 < 1.2.67
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.