Sceawere

Vulnerability Detail

CVE-2026-103514UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP 2FA TOTP Replay Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
13h ago
Vendor
Unknown
Product
WP 2FA
Attack Type
CWE-287 Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-03T06:16:40.740Z",
  "pubdate": "2026-10-03T06:16:40.740Z",
  "executiveSummary": "The WP 2FA WordPress plugin, specifically versions prior to 4.1.0, contains a critical security flaw involving the improper validation of Time-based One-Time Passcodes (TOTP). The vulnerability stems from a failure to implement a state-based tracking mechanism to invalidate tokens once they have been successfully used within their designated time window.\nThis authentication bypass allows an attacker who has compromised a user's primary credentials—and subsequently intercepted a valid TOTP token—to reuse that same token multiple times until the validity period expires. The vulnerability impacts all users utilizing the 2FA functionality, including those with administrative privileges. The risk is significant, as it effectively renders the secondary layer of authentication susceptible to replay attacks, thereby facilitating unauthorized access to sensitive WordPress environments. Exploitation requires the attacker to possess the victim's account password and access to a previously used but still valid TOTP code.",
  "technicalDetails": "The root cause of this vulnerability is a design flaw in the WP 2FA authentication handler, where the application fails to enforce the 'one-time' requirement of the Time-based One-Time Password (TOTP) algorithm defined in RFC 6238. In a secure implementation, the server must track used tokens and associated timestamps to ensure that a specific token is never accepted twice during its validity interval. The affected version of WP 2FA performs a validation check against the shared secret and the current time slice but neglects the state check required to prevent reuse.\nThe exploitation flow proceeds as follows: First, an attacker must obtain the victim's primary WordPress account password, potentially through credential stuffing, phishing, or other common account takeover vectors. Second, the attacker must capture a valid TOTP code while it is active. This can be achieved through a man-in-the-middle (MITM) attack if the connection is insecure, side-channel observation, or by tricking the user into providing the code. Third, the attacker initiates a login request using the compromised credentials. When prompted for the 2FA factor, the attacker inputs the captured TOTP code.\nBecause the server fails to invalidate the token after the first successful submission, the session is authenticated as the target user. If the attacker initiates subsequent requests before the TOTP window expires (typically 30-60 seconds), the same token remains valid for re-submission. This allows the attacker to bypass the authentication flow on subsequent attempts or use the token across multiple concurrent sessions if the server-side session management also relies on the initial 2FA success without secondary gating. The lack of token revocation upon utilization represents a critical failure in the plugin's authentication logic, as it undermines the core security objective of 2FA—ensuring that a stolen factor cannot be recycled for unauthorized access."
}
CVE-2026-103514: WP 2FA TOTP Replay Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere