CyberRota Analysis
AI-GeneratedThe WP 2FA WordPress plugin prior to version 3.1.1.2 is vulnerable as it fails to verify that the email address provided during two-factor authentication setup matches the user's account. This oversight allows attackers with valid user credentials to redirect verification codes to their own email, enabling account takeover. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account.