WP 2FA – Two-factor authentication for WordPress <= 2.9.3 - 2-Factor Authentication Bypass

2025-11-03 00:00
Benjamin Nadarević

Strategic Overview

Status
Patched in 3.0.0
Affected Version<= 2.9.3
CVSS5.3Medium
CVECVE-2025-12628
View all WP 2FA – Two-factor authentication for WordPress vulnerabilities

Vulnerability Overview

The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to 2FA bypass in all versions up to, and including, 2.9.3. This makes it possible for unauthenticated attackers to bypass 2FA protection. Please note Wordfence does not consider this a security vulnerability and previously rejected assigning a CVE ID to this issue. This is being included for informational purposes.

Technical Analysis

REMEDIATION: Update to version 3.0.0, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C