🔐 CVE Alert

CVE-2024-10924

CRITICAL 9.8

Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

CWE CWE-288
Vendor really simple plugins
Product really simple security pro multisite
Published Nov 15, 2024
Last Updated Jan 23, 2026
Stay Ahead of the Next One

Get instant alerts for really simple plugins really simple security pro multisite

Be the first to know when new critical vulnerabilities affecting really simple plugins really simple security pro multisite are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Really Simple Plugins / Really Simple Security Pro multisite
9.0.0 ≤ 9.1.1.1
rogierlankhorst / Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
9.0.0 ≤ 9.1.1.1
Really Simple Plugins / Really Simple Security Pro
9.0.0 ≤ 9.1.1.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/7d5d05ad-1a7a-43d2-bbbf-597e975446be?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L67 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L277 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L278 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3188431/really-simple-ssl wordfence.com: https://www.wordfence.com/blog/2024/11/really-simple-security-vulnerability/ github.com: https://github.com/JoshuaProvoste/0-click-RCE-Exploit-for-CVE-2024-10924

Credits

István Márton