6.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Description
The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them
Basic Information
ID
CVE-2025-12628
Source
WPScan
Published
Nov 24, 2025 at 12:58
Modified
Nov 24, 2025 at 15:09
Affected Product
Vendor
Unknown
Product
WP 2FA
Affected Versions
Unknown WP 2FA 0