WordPress Plugin Vulnerabilities
WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay
Description
The plugin does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
AUTHBYPASS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Suhayb Ahmed (cyboltx)
Submitter
Suhayb Ahmed (cyboltx)
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-01 (about 2 days ago)
Added
2026-10-01 (about 1 day ago)
Last Updated
2026-10-01 (about 1 day ago)