PT-2024-8207 · WordPress · Really Simple Security

István Márton

·

Published

2024-11-06

·

Updated

2026-05-16

·

CVE-2024-10924

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Really Simple Security (Free, Pro, and Pro Multisite) versions 9.0.0 through 9.1.1.1
Description The Really Simple Security plugins for WordPress are affected by an authentication bypass issue. This is due to improper user check error handling in the two-factor REST API actions with the check login and get user function. This allows unauthenticated attackers to log in as any existing user on the site, including administrators, when the "Two-Factor Authentication" setting is enabled. This vulnerability, tracked as CVE-2024-10924, has a CVSS score of 9.8 (Critical) and impacts over 4 million WordPress sites. The vulnerability is actively exploited in the wild. Attackers can bypass two-factor authentication and gain full administrative access to vulnerable sites. The check login and get user function is involved in the authentication process.
Recommendations Update Really Simple Security to version 9.1.2 or later.

Exploit

Fix

Missing Authentication

Improper Authentication

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09749
CVE-2024-10924

Affected Products

Really Simple Security