critical · CVSS v3 9.8
CVE-2026-103514
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allow…
Description
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.
Scores
- Severity
- critical
- CVSS v2
- 6.4
- CVSS v3
- 9.8
- CVSS v4
- —
- EPSS
- —