{"id":"CVE-2026-103514","title":"The WP 2FA  WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay i…","summary":"The WP 2FA  WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay i…","severity":"none","cwe":["CWE-287"],"product":"WP 2FA","affected":["wp_2fa < 4.1.0"],"published":"2026-10-03","updated":"2026-10-03","sourceUpdated":"2026-10-03T06:16:40.740","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103514","references":[{"url":"https://wpscan.com/vulnerability/e05aa5a3-cd04-428a-b6bb-0538ca1f6b4a/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-03T06:39:57.560Z","slug":"CVE-2026-103514","body":"## Overview\n\nThe WP 2FA  WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}