Authorization Bypass Vulnerability in Really Simple Security Plugin for WordPress
CVE-2026-82519

2.3LOW

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82519?

The Really Simple Security plugin for WordPress before version 9.8.2 exhibits a missing authorization check vulnerability. Authenticated low-privileged attackers can exploit this flaw to bypass two-factor authentication (2FA) indefinitely. The vulnerability resides in the profile-page update handler, where an unguarded code path allows attackers to send a specially crafted POST request that omits the two-factor-authentication field. This bypasses nonce verification and triggers the delete_two_fa_meta() function, resetting the 2FA grace period anchor timestamp on each login cycle, effectively deferring mandatory 2FA enforcement indefinitely and exposing users to increased risk.

Affected Version(s)

Really Simple Security 0 < 9.8.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Holmquist
.