CVE-2026-12988: Unknown Wp 2fa
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account.
Affected products
- Unknown Wp 2fa: before 3.1.1.2 (fixed in 3.1.1.2)
Published 2026-07-14. Last modified 2026-07-14.