CVE-2026-103514: CWE-287 Improper Authentication in WP 2FA
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.
AI Analysis
Technical Summary
CVE-2026-103514 describes an improper authentication vulnerability (CWE-287) in the WP 2FA WordPress plugin prior to version 4.1.0. The vulnerability arises because the plugin does not invalidate a time-based one-time passcode once it has been used. Consequently, an attacker with knowledge of an account's password and access to a valid TOTP within its time window can replay the code to bypass two-factor authentication protections, potentially gaining unauthorized access to accounts including those with administrative privileges.
Potential Impact
An attacker who has obtained both the account password and a valid time-based one-time passcode within its validity window can bypass the two-factor authentication mechanism. This compromises the security of accounts protected by WP 2FA, including administrator accounts, potentially allowing unauthorized access and control over the WordPress site.
Mitigation Recommendations
Upgrade the WP 2FA plugin to version 4.1.0 or later, where this vulnerability has been addressed. No other mitigation guidance is provided. Patch status is not explicitly stated but the presence of a fixed version (4.1.0) implies an official fix is available.
CVE-2026-103514: CWE-287 Improper Authentication in WP 2FA
Description
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.
CVSS v3.1
Score 7.5high
Affected software
WP 2FA
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-103514 describes an improper authentication vulnerability (CWE-287) in the WP 2FA WordPress plugin prior to version 4.1.0. The vulnerability arises because the plugin does not invalidate a time-based one-time passcode once it has been used. Consequently, an attacker with knowledge of an account's password and access to a valid TOTP within its time window can replay the code to bypass two-factor authentication protections, potentially gaining unauthorized access to accounts including those with administrative privileges.
Potential Impact
An attacker who has obtained both the account password and a valid time-based one-time passcode within its validity window can bypass the two-factor authentication mechanism. This compromises the security of accounts protected by WP 2FA, including administrator accounts, potentially allowing unauthorized access and control over the WordPress site.
Mitigation Recommendations
Upgrade the WP 2FA plugin to version 4.1.0 or later, where this vulnerability has been addressed. No other mitigation guidance is provided. Patch status is not explicitly stated but the presence of a fixed version (4.1.0) implies an official fix is available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-30T18:00:26.289Z
- State
- PUBLISHED
Threat ID: 6ac11723a43b0b3b89cacf64
Added to database: 10/03/2026, 14:54:27 UTC
Last enriched: 10/03/2026, 14:56:13 UTC
Last updated: 10/04/2026, 03:04:29 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.