CVE-2023-6272: Thememylogin 2fa

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

Affected products

Published 2023-12-18. Last modified 2026-06-17.