WordPress Plugin Vulnerabilities

WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay

Description

The plugin does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.

Proof of Concept

Affects Plugins

Fixed in 4.1.0

References

Classification

Miscellaneous

Original Researcher
Suhayb Ahmed (cyboltx)
Submitter
Suhayb Ahmed (cyboltx)
Verified
Yes

Timeline

Publicly Published
2026-10-01 (about 2 days ago)
Added
2026-10-01 (about 1 day ago)
Last Updated
2026-10-01 (about 1 day ago)

Other