OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103514

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-10-03 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The WP 2FA plugin for WordPress versions prior to 4.1.0 is vulnerable as it fails to invalidate a time-based one-time passcode after its initial use. This flaw allows attackers with knowledge of a user's password to replay a valid code within its validity period, effectively bypassing two-factor authentication and compromising accounts, including those of administrators. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of unauthorized access.

CVE
CVE-2026-103514
Severity
HIGH
CVSS
7.5
EPSS
0.30%
WordPress

Original NVD Description

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.