CVE-2026-103514 PUBLISHED

WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay

Assigner: WPScan
Reserved: 30.09.2026 Published: 03.10.2026 Updated: 03.10.2026

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.

Product Status

Vendor Unknown
Product WP 2FA
Versions Default: unaffected
  • affected from 0 to 4.1.0 (excl.)

Credits

  • Suhayb Ahmed (cyboltx) finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE