CVE-2026-100508: WordPress Two Factor plugin <= 0.16.0 - Denial of Service Attack vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.
Affected Software
1 affected component
WordPress Two Factor plugin<=0.16.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Two Factor pluginto a version that resolves this vulnerability.Fixed in 0.17.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other credentials to attempt exploitation over the network.
2
What is the expected impact?
The reported impact is denial of service, with availability rated as low impact. No confidentiality or integrity impact is indicated.
3
Which plugin versions are affected?
Two Factor plugin versions up to and including 0.16.0 are reported as affected.