CVE-2026-13690: Unknown Userswp

High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.

The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.

Affected products

  • Unknown Userswp: before 1.2.67 (fixed in 1.2.67)

Published 2026-07-29. Last modified 2026-07-30.