Sceawere
Vulnerability Detail
CVE-2026-103514UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP 2FA TOTP Replay Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- WP 2FA
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-03T06:16:40.740Z",
"pubdate": "2026-10-03T06:16:40.740Z",
"executiveSummary": "The WP 2FA WordPress plugin, specifically versions prior to 4.1.0, contains a critical security flaw involving the improper validation of Time-based One-Time Passcodes (TOTP). The vulnerability stems from a failure to implement a state-based tracking mechanism to invalidate tokens once they have been successfully used within their designated time window.\nThis authentication bypass allows an attacker who has compromised a user's primary credentials—and subsequently intercepted a valid TOTP token—to reuse that same token multiple times until the validity period expires. The vulnerability impacts all users utilizing the 2FA functionality, including those with administrative privileges. The risk is significant, as it effectively renders the secondary layer of authentication susceptible to replay attacks, thereby facilitating unauthorized access to sensitive WordPress environments. Exploitation requires the attacker to possess the victim's account password and access to a previously used but still valid TOTP code.",
"technicalDetails": "The root cause of this vulnerability is a design flaw in the WP 2FA authentication handler, where the application fails to enforce the 'one-time' requirement of the Time-based One-Time Password (TOTP) algorithm defined in RFC 6238. In a secure implementation, the server must track used tokens and associated timestamps to ensure that a specific token is never accepted twice during its validity interval. The affected version of WP 2FA performs a validation check against the shared secret and the current time slice but neglects the state check required to prevent reuse.\nThe exploitation flow proceeds as follows: First, an attacker must obtain the victim's primary WordPress account password, potentially through credential stuffing, phishing, or other common account takeover vectors. Second, the attacker must capture a valid TOTP code while it is active. This can be achieved through a man-in-the-middle (MITM) attack if the connection is insecure, side-channel observation, or by tricking the user into providing the code. Third, the attacker initiates a login request using the compromised credentials. When prompted for the 2FA factor, the attacker inputs the captured TOTP code.\nBecause the server fails to invalidate the token after the first successful submission, the session is authenticated as the target user. If the attacker initiates subsequent requests before the TOTP window expires (typically 30-60 seconds), the same token remains valid for re-submission. This allows the attacker to bypass the authentication flow on subsequent attempts or use the token across multiple concurrent sessions if the server-side session management also relies on the initial 2FA success without secondary gating. The lack of token revocation upon utilization represents a critical failure in the plugin's authentication logic, as it undermines the core security objective of 2FA—ensuring that a stolen factor cannot be recycled for unauthorized access."
}