The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them
Metrics
Affected Vendors & Products
References
History
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Mon, 24 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them | |
| Title | WP 2FA < 3.0.0 - Second Factor Bypass | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2025-11-24T12:58:37.015Z
Updated: 2025-11-24T15:09:10.780Z
Reserved: 2025-11-03T09:14:18.190Z
Link: CVE-2025-12628
Updated: 2025-11-24T15:08:27.768Z
Status : Awaiting Analysis
Published: 2025-11-24T13:16:01.223
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-12628
No data.