PT-2026-45694 · WordPress · Really Simple Security
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Really Simple Security WordPress plugin versions prior to 9.5.10.1
Description
The plugin fails to enforce the second-factor challenge in two of its two-factor authentication REST endpoints. This allows an attacker who possesses a user's password to obtain a WordPress authentication session without completing the email OTP (One-Time Password) challenge.
Recommendations
Update the plugin to version 9.5.10.1 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Really Simple Security