Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2026-07-01
CVE-2026-11883 - Webauthn Provider For Two Factor Plugin
The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an attacker who already knows a user's password to bypass the two-factor authentication requirement by submitting a malformed request.
PLUGIN
Webauthn Provider For Two Factor
CVE-2026-11883
Risk Score
