Impact
The WP 2FA WordPress plugin, when installed in a version before 4.1.0, fails to mark a time‑based one‑time password (TOTP) as used after a successful authentication. As a result, an attacker who has compromised a valid user password and has observed a TOTP within its short validity window can replay that code to obtain privileged access, including to administrator accounts. The vulnerability creates a successful bypass of the two‑factor authentication layer, allowing an attacker to elevate privileges and compromise confidentiality of the site. The weakness resides in the inadequate invalidation of a single‑use token, effectively permitting reuse of a TOTP without detecting it.
Affected Systems
This flaw affects the WP 2FA plugin for WordPress. All installations running a plugin version earlier than 4.1.0 are impacted. No other WordPress components are mentioned as affected.
Risk and Exploitability
The CVSS score is not provided, but the vulnerability permits direct, remote authentication bypass. Because no exploit code or public source is cited, the exploit probability is uncertain; EPSS data is not available. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to have or acquire a user’s password and observe or deduce a valid TOTP within its narrow time window. Once those prerequisites are satisfied, the attacker can replay the same TOTP to any target account, including administrators, gaining full control of the WordPress instance.
OpenCVE Enrichment