CVE-2026-62142: WordPress WP 2FA plugin <= 4.1.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Oct 8, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request Forgery.This issue affects WP 2FA: from n/a through 4.1.0.
Affected Software
1 affected component
Melapress WP 2FA<=4.1.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Melapress WP 2FA (wp-2fa)to a version that resolves this vulnerability.Fixed in 4.2.0
Event History
Oct 8, 2026
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an attacker account or administrative access?
No attacker privileges are required. However, exploitation requires user interaction, consistent with the UI:R attack vector.
2
Can the issue be triggered remotely?
Yes. The attack vector is network-based (AV:N), so an attacker can attempt exploitation remotely, provided they can cause a user to interact with the crafted request.
3
What could be affected if exploitation succeeds?
The vulnerability is rated as having high potential impact on confidentiality, integrity, and availability (C:H/I:H/A:H).