Starting October 1st, WordPress accounts that can push updates and changes to plugins and themes will be required to enable two-factor authentication (2FA) on their accounts.
See also: Malware targets gamers – Activision Blizzard recommends 2FA

The decision is part of the platform's plugin control team's effort to reduce the risk of unauthorized access, which could lead to supply chain attacks
"Accounts with commit access can push updates and changes to plugins and themes used by millions of WordPress websites worldwide," the announcement.
The security of these accounts is essential to prevent unauthorized access and maintain the safety and trust of the WordPress community, which is why enabling 2FA will now be required.
WordPress is an open-source content management system (CMS), blogging tool, and publishing platform that helps users create and manage websites. Users have access to a wide variety of free and paid themes and plugins that allow them to customize the appearance and extend the functionality of their sites.
A malicious actor who steals a publisher's account could change the code in a theme or plugin to include vulnerabilities or backdoors that would allow privileged access to third parties.
See also: Tycoon 2FA: New phishing platform bypasses 2FA in Microsoft 365 and Gmail

To prevent such risks, 2FA security must be enabled on October 1st for accounts with commit access to the WordPress platform. Account administrators can enable the setting from their account's security menu. Step-by-step instructions on how to enable 2FA are available here.
Additionally, WordPress.org has added SVN-specific passwords that separate access for making code changes from the main account credentials.
Plugin authors who use deployment scripts, such as GitHub Actions, will need to update their scripts to use the new SVN-specific passwords.
The team notes that technical limitations prevent implementing 2FA in existing code repositories and chose to combine “account-level two-factor authentication, high-entropy SVN passwords, and other security features.”
See also: How does two-factor authentication (2FA) enhance security?
Two-factor authentication (2FA), now required by WordPress, is a vital security measure that adds an extra layer of protection to online accounts. By requiring not only a password and username, but also something that only the user has—such as a physical token, a smartphone , or a code sent via text message—2FA significantly reduces the risk of unauthorized access. This process mitigates the vulnerabilities associated with traditional password systems, as even if an attacker obtains the password, they cannot access the account without the second factor. Implementing 2FA is essential for safeguarding sensitive information and strengthening overall cybersecurity.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
