Two Factor Authentication

UpdraftPlus, the backup and restore plugin for WordPress, has launched a two-factor authentication (TFA) plugin. The TFA plugin requires a one-time code in order to log in, and supports standard TOTP and HOTP protocols. It can be made available on a per-role basis and can be turned on or off by each user. The plugin also allows for trusted devices and encrypts TFA-generating secret keys using an on-disk encryption key. UpdraftPlus has over two million active installs.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Two Factor Authentication 1.1.10

    Fixed

    The two-factor-authentication plugin for WordPress

    Read More
  • Input validation vulnerability in Two Factor Authentication 1.3.13

    Fixed

    Cross Site Request Forgery (CSRF) is a type of attack that can be used to disable two-factor authentication (2FA) in a plugin for WordPress websites. The plugin

    Read More