Sceawere
Vulnerability Detail
CVE-2026-62142UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP 2FA CSRF Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 4h ago
- Vendor
- Melapress
- Product
- WP 2FA
- Attack Type
- Cross-Site Request Forgery (CSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request Forgery.This issue affects WP 2FA: from n/a through 4.1.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-08T13:17:18.553Z",
"pubdate": "2026-10-08T13:17:18.553Z",
"executiveSummary": "The WP 2FA plugin, developed by Melapress, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability affecting versions from n/a through 4.1.0.\nThis vulnerability occurs due to a lack of proper request validation, allowing an unauthenticated attacker to induce an authenticated administrator or user to perform unintended actions without their consent.\nThe primary risk involves the unauthorized execution of administrative tasks within the context of the affected user's session, which could lead to the modification of security settings or the compromise of 2FA configurations.\nExploitation requires the attacker to successfully lure a logged-in privileged user to a malicious site or trick them into interacting with a crafted request.\nSuccessful exploitation compromises the integrity of the plugin's security functions, potentially weakening the site's overall authentication posture.",
"technicalDetails": "The vulnerability originates from a deficiency in CSRF protection mechanisms, specifically the lack of mandatory anti-CSRF tokens or nonce validation in sensitive state-changing operations within the WP 2FA plugin.\nCSRF vulnerabilities manifest when an application fails to differentiate between legitimate user-initiated requests and malicious requests forged by an external site, provided the victim holds an active, authenticated session with the target application.\nIn this context, the affected component processes HTTP requests (typically POST or GET) that perform administrative or functional changes without verifying the origin of the request or ensuring the presence of a cryptographically secure, session-bound nonce.\nThe attack flow begins when an attacker identifies a vulnerable endpoint within WP 2FA. The attacker then constructs a malicious webpage or email containing an embedded script or a hidden form designed to submit a request to the target WordPress site on behalf of the victim.\nWhen a logged-in administrator visits the malicious page, the browser automatically includes the victim's session cookies in the forged request. Because the plugin does not perform sufficient server-side validation to ensure the request originated from the intended administrative dashboard, the server processes the request as a legitimate action.\nThe scope of impact is contingent upon the permissions of the victim; if an administrator is targeted, the attacker could manipulate plugin settings, disable 2FA requirements, or perform other modifications that undermine the security of the WordPress instance.\nThis vulnerability is classified as a client-side execution flaw, where the trust relationship between the user's browser and the web server is abused. The lack of strict Referer or Origin header checks, combined with the absence of nonce-based validation, facilitates the execution of unauthorized state changes.\nAffected versions range from the initial release (n/a) through version 4.1.0. The vulnerability is persistent across standard web browser environments where session cookies are utilized for persistent authentication."
}