The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
CVE-2026-13690
NONE
EPSS 0.18%
Updated Jul 29, 2026
WordPress
CVE Details
CVE ID
CVE-2026-13690
Published Date
Jul 29, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.18%
Likelihood of exploitation in next 30 days
Percentile:
8.0th percentile (higher than 8.0% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory