CVE-2026-13690: Unknown Userswp
High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
Affected products
- Unknown Userswp: before 1.2.67 (fixed in 1.2.67)
Published 2026-07-29. Last modified 2026-07-30.