Executive brief
A vulnerability in the WP 2FA plugin for WordPress allows attackers to hijack the two-factor authentication (2FA) setup process. If an attacker gains a user's password, they can complete the 2FA enrollment using their own email address instead of the user's. This results in a full account takeover, locking the legitimate owner out of their account and requiring administrative intervention to restore access.
Technical details
The WP 2FA plugin fails to validate the email address provided during the initial 2FA enrollment wizard against the user's registered account email. An attacker who has obtained a user's primary credentials (e.g., via phishing or credential stuffing) can log in and, if the account has not yet completed 2FA setup, intercept the setup process. By sending a crafted AJAX request to 'send_authentication_setup_email' with an attacker-controlled email address, the attacker can receive the verification code, complete enrollment, and bind the account's 2FA to their own mailbox. This bypasses intended restrictions where codes should only be sent to the registered user's email. The issue is fixed in version 3.1.1.2.
Affected products
- Melapress WP 2FA < 3.1.1.2
Timeline
- 2026-06-23: disclosed: Original researcher disclosure
- 2026-07-14: advisory: NVD and WPScan advisory published
- 2026-07-14: patched: Fixed in version 3.1.1.2