Vulnerability in Two Factor — CVE-2026-100508
HighSeverity
—Estimated exploit probability
100,000+ sitesInstalls
0.17.0Fixed in
What to do now
Update Two Factor to 0.17.0 or later.
Affected versions
- Everything up to and including 0.16.0
Affected: Two Factor (plugin, two-factor)
What the vulnerability is
The Two Factor plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 0.16.0. This is due to insufficient validation of user supplied input. This makes it possible for unauthenticated attackers to make the affected site unavailable.