Resetting password bypasses 2FA
-
Hi guys,
We’re using your plugin in combination with WooCommerce. We’ve noticed that when resetting your password on a 2FA secured account via the WooCommerce “forgot password” form, the user is being logged in without being asked for 2FA during the initial sign in process.
Logging out and back in, after resetting the password, will prompt for 2FA again. So, it seems to happen only when the user is being logged in during the reset request.
I would consider this a security risk, but I would like to hear your opinion on this. Is it intentional behavior?
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘Resetting password bypasses 2FA’ is closed to new replies.