Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 14 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Tue, 14 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account. | |
| Title | WP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-14T12:24:36.125Z
Reserved: 2026-06-23T11:48:46.764Z
Link: CVE-2026-12988
Updated: 2026-07-14T12:24:30.377Z
Status : Deferred
Published: 2026-07-14T06:17:11.677
Modified: 2026-07-14T16:42:11.910
Link: CVE-2026-12988
No data.
OpenCVE Enrichment
Updated: 2026-07-31T11:00:06Z