The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 24 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them | |
| Title | WP 2FA < 3.0.0 - Second Factor Bypass | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-11-24T15:09:10.780Z
Reserved: 2025-11-03T09:14:18.190Z
Link: CVE-2025-12628
Updated: 2025-11-24T15:08:27.768Z
Status : Awaiting Analysis
Published: 2025-11-24T13:16:01.223
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-12628
No data.
OpenCVE Enrichment
No data.