Authentication Bypass Vulnerability in Two-Factor Authentication
Key Information
- Vendor
- Really Simple Plugins
- Status
- Really Simple Security Pro Multisite
- Really Simple Security – Simple And Performant Security (formerly Really Simple Ssl)
- Really Simple Security Pro
- Vendor
- CVE Published:
- 15 November 2024
Badges
Summary
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are affected by a critical authentication bypass vulnerability, tracked as CVE-2024-10924, with a high CVSS score of 9.8. This vulnerability can allow unauthenticated attackers to log in as any existing user on the site, including administrators, when the "Two-Factor Authentication" setting is enabled. It affects over 4 million WordPress sites. The vulnerability was patched in version 9.1.2, released after responsible disclosure, but there is a risk of exploitation due to the large number of affected sites. Exploitation could lead to hijacking of WordPress sites and further use for criminal purposes. There is no mention of known exploits by ransomware groups at this time.
Affected Version(s)
Really Simple Security Pro multisite <= 9.1.1.1
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.1.1.1
Really Simple Security Pro <= 9.1.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
CVE-2024-10924, authentication bypass vulnerability in WordPress
Vulnerability CVE-2024-10924 in the Really Simple Security plugin allows an attacker to log onto a WordPress site with administrator rights.
15 hours ago
Urgent: Critical WordPress Plugin Vulnerability Exposes Over 4 Million Sites
Critical vulnerability (CVE-2024-10924) in Really Simple Security plugin allows attackers admin access to WordPress sites. Over 4 million affected.
3 days ago
CVSS V3.1
Timeline
- 👾
Exploit exists.
Vulnerability started trending.
First article discovered by The Hacker News
Vulnerability published.
Disclosed
Vulnerability Reserved.
Discovered
Vendor Notified