What is CVE-2026-15372?
CVE-2026-15372 allows an attacker who knows the password to bypass two-factor authentication in the WP 2FA WordPress plugin before version 4.1.0 due to missing validation of the second factor, gaining full account access including administrator accounts. Update the plugin to version 4.1.0 or later.
Azərbaycanca: CVE-2026-15372, 4.1.0 versiyasından əvvəlki WP 2FA WordPress pluginində ikinci faktorun düzgün doğrulanmaması səbəbindən, parolu bilən şəxs autentifikasiyanı keçərək hesaba, o cümlədən administrator hesabına tam giriş əldə edə bilər. Plugin yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
What can CVE-2026-15372 cause in the WP 2FA plugin?
An attacker who knows the password can bypass two-factor authentication due to missing validation of the second factor, gaining full account access including administrator accounts.
How can I protect against CVE-2026-15372?
You should update the WP 2FA WordPress plugin to version 4.1.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.