CVE-2025-10293
HIGHKeyy Two Factor Authentication (like Clef) plugin for WordPress <1....
Title source: llmDescription
The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity associated with a token generated. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate valid auth tokens and leverage that to auto-login as other accounts, including administrators, as long as the administrator has the 2FA set up.
References (2)
Core 2
Core References
Scores
CVSS v3
8.8
EPSS
0.0034
EPSS Percentile
25.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-287
Status
published
Products (1)
nexist/Keyy Two Factor Authentication (like Clef)
< 1.2.3
Published
Oct 15, 2025
Tracked Since
Feb 18, 2026