CVE-2025-12628 Details
Description
The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them
A vulnerability exists in the WP 2FA WordPress plugin, affecting versions prior to 3.0.0, due to the plugin's backup codes lacking sufficient entropy. This deficiency could enable attackers to brute force the codes and bypass the two-factor authentication (2FA) requirement. The vulnerability arises because the backup codes can be easily guessed or calculated, undermining the security of the 2FA mechanism.
Users are advised to update the WP 2FA WordPress plugin to version 3.0.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 24, 2025CISA-ADP
Assessed Nov 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/5e2d033c-dde6-4774-8588-cbe268c0d797/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| WP 2FA | < 3.0.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 24, 2025 | CVE Modified | CISA-ADP |
| Nov 24, 2025 | New CVE Received | [email protected] |
Volerion