logo

WordPress.org to require 2FA for plugin developers by October

ID: 6d6d82cd-af42-5613-ba17-04f6cf765633

STIX ID: report--6d6d82cd-af42-5613-ba17-04f6cf765633

Feed Name: Bleeping Computer

Date Published: 2024-09-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

WordPress.org will require two-factor authentication (2FA) for all accounts with commit access to plugins and themes starting October 1 to reduce supply-chain risk, and has introduced high-entropy, SVN-specific passwords to separate code push credentials from main accounts. Plugin authors using automated deployments (e.g., GitHub Actions) must update scripts to use the new SVN credentials, while the platform combines account-level 2FA and deploy-time controls due to technical limits on enforcing 2FA for existing repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.