CVE-2026-11883: Unknown Webauthn Provider For Two Factor

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an attacker who already knows a user's password to bypass the two-factor authentication requirement by submitting a malformed request.

Affected products

  • Unknown Webauthn Provider For Two Factor: before 2.5.6 (fixed in 2.5.6)

Published 2026-07-01. Last modified 2026-07-01.