CVE-2026-103514
Received Received - Intake

Time-of-Use Bypass in WP 2FA WordPress Plugin

Vulnerability report for CVE-2026-103514, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: WPScan

Description

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_2fa wp_2fa to 4.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WP 2FA WordPress plugin before version 4.1.0 has a flaw where it does not invalidate a time-based one-time passcode (TOTP) after use. This allows an attacker who knows a user's password and has seen a valid TOTP code within its validity window to replay that code and bypass two-factor authentication, even for administrator accounts.

Detection Guidance

Check the installed version of the WP 2FA plugin. If it is below 4.1.0, the system is vulnerable. This can be done by inspecting the plugin files or using WordPress admin panel to view the plugin version.

Impact Analysis

If you use the WP 2FA plugin version below 4.1.0, an attacker could bypass your two-factor authentication by replaying a previously used TOTP code. This means they could gain unauthorized access to your account even if you have 2FA enabled, potentially leading to data theft, unauthorized actions, or full account compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements such as GDPR (data protection) or HIPAA (health information security). Organizations using the affected plugin versions may face legal and regulatory penalties due to insufficient authentication controls.

Mitigation Strategies

Update the WP 2FA plugin to version 4.1.0 or later immediately to patch the vulnerability. If updating is not possible, consider disabling the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103514. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart