CVE-2026-13690
UsersWP < 1.2.67 - Two-Factor Authentication Bypass
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
| Vendor | unknown |
| Product | userswp |
| Published | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown userswp
Be the first to know when new unknown vulnerabilities affecting unknown userswp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / UsersWP
0 < 1.2.67
References
Credits
dc11 WPScan