The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
We have discovered 3,156 live websites that are affected by CVE-2026-13690.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 3,156 live websites (94% of Userswp install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 95 versions ( 99% of all versions) |
| 1,226 websites | |
| 330 websites | |
| 216 websites | |
| 153 websites | |
| 129 websites | |
| 85 websites | |
| 82 websites | |
| 76 websites | |
| 75 websites | |
| 74 websites |
| .com | 1,335 websites |
| .org | 306 websites |
| .de | 194 websites |
| .co.uk | 118 websites |
| .it | 106 websites |
| .net | 87 websites |
| .ca | 55 websites |
| .fr | 54 websites |
| .com.au | 52 websites |
| .nl | 49 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | *,*** | ||
| **********.id | **,*** | ||
| *******.org | **,*** | ||
| *********.com | **,*** | ||
| ************************.de | **,*** | ||
| ***********.org | **,*** | ||
| ****************.com | ***,*** | ||
| ********.com | ***,*** | ||
| *****.*******.io | ***,*** | ||
| ***.ua | ***,*** |
FAQ