CVE-2026-103514
WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.
| Vendor | unknown |
| Product | wp 2fa |
| Published | Oct 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp 2fa
Be the first to know when new unknown vulnerabilities affecting unknown wp 2fa are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP 2FA
0 < 4.1.0
References
Credits
Suhayb Ahmed (cyboltx) WPScan