PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103514 WP 2FA CVE debrief

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts. This vulnerability can lead to unauthorized access on WordPress installations. Defenders should assess exposure and verify the use of version 4.1.0 or later. The CVE record and NVD entry provide limited information about the vulnerability.

Vendor
WP 2FA
Product
WP 2FA
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for WordPress installations using the WP 2FA plugin should assess exposure and verify the use of version 4.1.0 or later. This includes administrators, security teams, and vulnerability management teams who need to ensure that two-factor authentication is properly configured and enforced.

Why it matters

The WP 2FA plugin vulnerability allows an attacker to bypass two-factor authentication, potentially leading to unauthorized access on WordPress installations.

  • Potential bypass of two-factor authentication on administrator accounts
  • Possible replay attacks using valid time-based one-time passcodes
  • Verification of WP 2FA plugin version and configuration required
  • Monitoring for potential attacks on WordPress installations

Technical summary

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts. This vulnerability can lead to unauthorized access on WordPress installations. The vulnerability class is related to authentication bypass, and defenders should focus on verifying the use of version 4.1.0 or later.

Defensive priority

Defenders should prioritize verifying the use of WP 2FA version 4.1.0 or later, and ensure that two-factor authentication is properly configured and enforced.

Recommended defensive actions

  • Verify the use of WP 2FA version 4.1.0 or later
  • Ensure that two-factor authentication is properly configured and enforced
  • Monitor for potential replay attacks on administrator accounts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability, but indicate that the WP 2FA plugin before version 4.1.0 does not invalidate time-based one-time passcodes after use. The official CVE Program record and NIST NVD detail page offer source-provided CVE metadata and source-specific vulnerability assessment. However, additional verification is required to confirm affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103514 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103514

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103514 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103514

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.