Authorization Bypass Vulnerability in Really Simple Security Plugin for WordPress
CVE-2026-82519
2.3LOW
What is CVE-2026-82519?
The Really Simple Security plugin for WordPress before version 9.8.2 exhibits a missing authorization check vulnerability. Authenticated low-privileged attackers can exploit this flaw to bypass two-factor authentication (2FA) indefinitely. The vulnerability resides in the profile-page update handler, where an unguarded code path allows attackers to send a specially crafted POST request that omits the two-factor-authentication field. This bypasses nonce verification and triggers the delete_two_fa_meta() function, resetting the 2FA grace period anchor timestamp on each login cycle, effectively deferring mandatory 2FA enforcement indefinitely and exposing users to increased risk.
Affected Version(s)
Really Simple Security 0 < 9.8.2