← WordPress Vulnerabilities
WordPress security by component

Two Factor (2FA) Authentication via Email

Two Factor (2FA) Authentication via Email is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Feb 19, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: two-factor-2fa-via-email

CVE-2025-13587: Two Factor (2FA) Authentication via Email: Privilege escalation or authentication bypass

Two Factor (2FA) Authentication via Email is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.

PublishedFeb 19, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 19, 2026 CVE-2025-13587
Two Factor (2FA) Authentication via Email: Privilege escalation or authentication bypass
Two Factor (2FA) Authentication via Email is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE6.5
NVDPending