Title: Wordfence 2FA implementation question
Last modified: December 22, 2022

---

# Wordfence 2FA implementation question

 *  Resolved [sel](https://wordpress.org/support/users/glashsix/)
 * (@glashsix)
 * [3 years, 7 months ago](https://wordpress.org/support/topic/wordfence-2fa-implementation-question/)
 * Hi, Wordfence team,
 * I’ve come across WPScan’s [Note On 2FA Plugin Vulnerabilities](https://blog.wpscan.com/a-note-on-2fa-plugin-vulnerabilities/)
   and was wondering whether some of the 2FA bad implementation practices apply 
   to Wordfence or Wordfence is not one of the vendors?
 * Thanks!

Viewing 3 replies - 1 through 3 (of 3 total)

 *  Plugin Support [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * (@wfpeter)
 * [3 years, 7 months ago](https://wordpress.org/support/topic/wordfence-2fa-implementation-question/#post-16358861)
 * Hi [@glashsix](https://wordpress.org/support/users/glashsix/), thanks for your
   question!
 * We did receive feedback on how to improve our 2FA secret handling from an independent
   security researcher during 2022, and have implemented some improvements based
   on this feedback. At no point were 2FA secrets directly threatened – any exploitation
   would have required an attacker to have already compromised a site database, 
   which would involve finding an unpatched SQL injection vulnerability on a site
   as well as bypassing the Wordfence firewall’s built-in SQL injection protection.
 * For the vast majority of our users’ threat models, having functional, easy-to-
   use 2FA is a significant security improvement. The implementation improvements
   simply added additional roadblocks to slow down an attacker in the extremely 
   unlikely event that they made it past the first few security layers. We strive
   to align our implementation with best practices to the maximum extent practical
   in a WordPress environment while maintaining compatibility for as many customers
   as possible.
 * Thanks,
   Peter.
 *  Thread Starter [sel](https://wordpress.org/support/users/glashsix/)
 * (@glashsix)
 * [3 years, 7 months ago](https://wordpress.org/support/topic/wordfence-2fa-implementation-question/#post-16360293)
 * Hi Peter,
 * I understand. Thank you for your answer and clarification 🙂
 * Bests
 *  Plugin Support [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * (@wfpeter)
 * [3 years, 7 months ago](https://wordpress.org/support/topic/wordfence-2fa-implementation-question/#post-16361703)
 * No worries, always happy to help. If you have further Wordfence questions in 
   future, by all means start up a new topic any time.
 * Peter.

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Wordfence 2FA implementation question’ is closed to new replies.

 * ![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)
 * [Wordfence Security - Firewall, Malware Scan, and Login Security](https://wordpress.org/plugins/wordfence/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wordfence/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wordfence/)
 * [Active Topics](https://wordpress.org/support/plugin/wordfence/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wordfence/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

## Tags

 * [2fa](https://wordpress.org/support/topic-tag/2fa/)

 * 4 replies
 * 2 participants
 * Last reply from: [wfpeter](https://wordpress.org/support/users/wfpeter/)
 * Last activity: [3 years, 7 months ago](https://wordpress.org/support/topic/wordfence-2fa-implementation-question/#post-16361703)
 * Status: resolved