VYPR

Two Factor Authentication

by WordPress

Source repositories

CVEs (3)

  • CVE-2018-20231HigDec 19, 2018
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation.

  • CVE-2015-9355MedAug 28, 2019
    risk 0.40cvss 6.1epss 0.01

    The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area.

  • CVE-2026-8903MedMay 27, 2026
    risk 0.28cvss 4.3epss 0.00

    The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the ipv_save_changes function. This makes it possible for…