CVE-2026-89080
Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demotion
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
| Vendor | unknown |
| Product | really simple security |
| Published | Sep 13, 2026 |
| Last Updated | Sep 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown really simple security
Be the first to know when new high vulnerabilities affecting unknown really simple security are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Really Simple Security
9.5.10.1 < 9.8.1
References
Credits
Charles Vosburgh WPScan