PatchSiren cyber security CVE debrief
CVE-2026-103514 WP 2FA CVE debrief
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts. This vulnerability can lead to unauthorized access on WordPress installations. Defenders should assess exposure and verify the use of version 4.1.0 or later. The CVE record and NVD entry provide limited information about the vulnerability.
- Vendor
- WP 2FA
- Product
- WP 2FA
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for WordPress installations using the WP 2FA plugin should assess exposure and verify the use of version 4.1.0 or later. This includes administrators, security teams, and vulnerability management teams who need to ensure that two-factor authentication is properly configured and enforced.
Why it matters
The WP 2FA plugin vulnerability allows an attacker to bypass two-factor authentication, potentially leading to unauthorized access on WordPress installations.
- Potential bypass of two-factor authentication on administrator accounts
- Possible replay attacks using valid time-based one-time passcodes
- Verification of WP 2FA plugin version and configuration required
- Monitoring for potential attacks on WordPress installations
Technical summary
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts. This vulnerability can lead to unauthorized access on WordPress installations. The vulnerability class is related to authentication bypass, and defenders should focus on verifying the use of version 4.1.0 or later.
Defensive priority
Defenders should prioritize verifying the use of WP 2FA version 4.1.0 or later, and ensure that two-factor authentication is properly configured and enforced.
Recommended defensive actions
- Verify the use of WP 2FA version 4.1.0 or later
- Ensure that two-factor authentication is properly configured and enforced
- Monitor for potential replay attacks on administrator accounts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, but indicate that the WP 2FA plugin before version 4.1.0 does not invalidate time-based one-time passcodes after use. The official CVE Program record and NIST NVD detail page offer source-provided CVE metadata and source-specific vulnerability assessment. However, additional verification is required to confirm affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103514 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103514
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103514 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103514
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/e05aa5a3-cd04-428a-b6bb-0538ca1f6b4a/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.