Home

Description

The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them

PUBLISHED Reserved 2025-11-03 | Published 2025-11-24 | Updated 2025-11-24 | Assigner WPScan

Problem types

CWE-331 Insufficient Entropyy

Product status

Default status
unaffected

Any version before 3.0.0
affected

Credits

Benjamin Nadarević finder

WPScan coordinator

References

wpscan.com/...rability/5e2d033c-dde6-4774-8588-cbe268c0d797/ exploit vdb-entry technical-description

cve.org (CVE-2025-12628)

nvd.nist.gov (CVE-2025-12628)

Download JSON