CVE 6.3 MEDIUM

WP 2FA < 3.0.0 - Second Factor Bypass_CVE-2025-12628

6.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Description

The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them

Basic Information

ID CVE-2025-12628
Source WPScan
Published Nov 24, 2025 at 12:58
Modified Nov 24, 2025 at 15:09

Affected Product

Vendor Unknown
Product WP 2FA
Affected Versions Unknown WP 2FA 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.