logo

Vulnerability Undermines WordPress Two-Factor Plugins

ID: 6bca906f-55af-5949-8c88-f30d227d75e4

STIX ID: report--6bca906f-55af-5949-8c88-f30d227d75e4

Feed Name: Security Ledger

Threat Score
50/100

Date Published: 2014-02-14

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

Duo Security disclosed a vulnerability in WordPress multisite deployments where certain per-site 2FA plugins (including Duo’s) can be bypassed: a user with valid username/password for one site in a multisite network may be able to log into another site without completing the second-factor. The issue affects multisite configurations only, does not impact single-site deployments, and Duo has contacted WordPress and other plugin publishers to address the bug.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.