Cross-Site Request Forgery Vulnerability in Two-Factor Authentication Plugin for WordPress
CVE-2026-8903
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-8903?
The Two-factor authentication (previously known as IP Vault) plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in the ipv_save_changes function. This vulnerability allows unauthenticated attackers to manipulate the plugin's firewall and two-factor authentication settings by tricking a site administrator into executing an action, such as clicking a malicious link. As a result, an attacker could potentially disable critical security features, leading to severe security implications for affected WordPress sites.
Affected Version(s)
Two-factor authentication (formerly IP Vault) 0 <= 2.1