HomeDefault status
unaffected
Any version before 3.0.0
affected
Description
The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them
Problem types
Product status
Any version before 3.0.0
Credits
Benjamin Nadarević
WPScan
References
wpscan.com/...rability/5e2d033c-dde6-4774-8588-cbe268c0d797/