Sceawere
Vulnerability Detail
CVE-2026-100508UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Two Factor Unauthenticated DoS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- WordPress.org
- Product
- Two Factor
- Attack Type
- CWE-770 Allocation of Resources Without Limits or Throttling
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-30T13:17:15.203Z",
"pubdate": "2026-09-30T13:17:15.203Z",
"executiveSummary": "A Denial of Service (DoS) vulnerability exists in Two Factor versions 0.16.0 and earlier, allowing unauthenticated remote attackers to compromise service availability.\nThe vulnerability manifests as an application-level exhaustion attack, where an attacker can trigger resource depletion without requiring valid credentials or prior authentication.\nThe impact is significant, as successful exploitation results in the inability of legitimate users to access two-factor authentication services, potentially locking users out of protected systems.\nThis vulnerability poses a high risk to business continuity, as the attack vector is network-accessible and requires minimal technical sophistication to initiate.\nAttackers can leverage this flaw to perform persistent service disruption, impacting the integrity of authentication workflows and overall system availability.",
"technicalDetails": "The vulnerability resides within the request handling mechanism of the Two Factor plugin, specifically affecting how it processes incoming requests before authentication validation occurs.\nThe root cause is an improper input validation or resource management logic that fails to restrict the rate or volume of processing for unauthenticated requests destined for authentication-related endpoints.\nBecause the vulnerable component triggers intensive operations—such as cryptographic calculations, database lookups, or session initialization—before verifying the legitimacy of the request, an attacker can flood the server with malformed or excessive requests.\nThe attack flow begins when an unauthenticated actor sends a high volume of specifically crafted requests to the Two Factor service endpoints. Because these requests do not require an active session token or valid credentials, the application attempts to process each one synchronously.\nAs the application processes these requests, it consumes significant CPU cycles and memory resources. In a state-constrained environment, this leads to thread starvation or memory exhaustion. Once the resources reach a critical threshold, the application becomes unable to process legitimate authentication requests, resulting in a system-wide Denial of Service.\nThe flaw affects Two Factor versions 0.16.0 and all prior releases. Since the vulnerable code path is exposed globally through the network interface, any endpoint reachable by an attacker can be used to facilitate the DoS condition.\nExploitation does not require elevated privileges, as the entry point is explicitly designed to handle requests from users who have not yet successfully authenticated. Consequently, the attacker operates entirely outside the perimeter of standard security controls.\nPost-exploitation, the server may experience significant latency, increased error rates (such as 5xx status codes), or a complete crash of the authentication service, rendering the Two Factor mechanism ineffective and effectively bypassing the intended security controls by rendering them unavailable."
}