Medium 6.3
2025-11-24< 3.0.0
CVE-2025-12628
Minimum safe version
3.0.0
Update to 3.0.0 or later to address 12 fixable vulnerabilities
CVE-2025-12628
CVE-2022-44587
CVE-2024-32568
CVE-2023-6520
CVE-2023-6506
WP 2FA < 2.2.0 - Arbitrary 2FA Disabling via IDOR
WP 2FA – Two-factor authentication for WordPress <= 2.1.0 - Insecure Direct Object Reference
CVE-2022-44595
WordPress WP 2FA Plugin <= 2.2.0 is vulnerable to Broken Authentication
WordPress WP 2FA Plugin <= 2.2.1 is vulnerable to Sensitive Data Exposure
WordPress WP 2FA Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS)
WordPress WP 2FA plugin <= 2.1.0 - Arbitrary 2FA Disabling via Insecure Direct Object References (IDOR) vulnerability