WordPress · Wp 2Fa · CVE-2026-12988
**Name of the Vulnerable Software and Affected Versions**
WP 2FA versions prior to 3.1.1.2
**Description**
The plugin fails to verify if the email address provided during the two-factor authentication setup belongs to the user. This allows an attacker with valid user credentials to redirect the setup verification code to an email address under their control, leading to full account takeover.
**Recommendations**
Update to version 3.1.1.2 or later.