SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-12988

MEDIUM · CVSS 6.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The WP 2FA WordPress plugin prior to version 3.1.1.2 is vulnerable as it fails to verify that the email address provided during two-factor authentication setup matches the user's account. This oversight allows attackers with valid user credentials to redirect verification codes to their own email, enabling account takeover. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-12988
Severity
MEDIUM
CVSS
6.4
EPSS
0.17%
WordPress

Original NVD Description

The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account.