CVE-2025-12628: Unknown Wp 2fa
Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them
Affected products
- Unknown Wp 2fa: before 3.0.0 (fixed in 3.0.0)
Published 2025-11-24. Last modified 2026-10-08.