CVE-2025-12628
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/11/2025
Last modified:
25/11/2025
Description
The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM



