CVE-2025-12628: Unknown Wp 2fa

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them

Affected products

  • Unknown Wp 2fa: before 3.0.0 (fixed in 3.0.0)

Published 2025-11-24. Last modified 2026-10-08.