CVE Database /
CVE-2024-10924
CVE · Critical
CVE-2024-10924 — Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] >= 9.0.0 - <= 9.1.1.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-10924
|
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] >= 9.0.0 - <= 9.1.1.1 |
Authentication Bypass Using an Alternate Path or Channel |
Critical
9.8
|
9.0.0–9.1.2
|
9.1.2 |
2024-11-14 |
—
|
CVE-2024-10924
The Really Simple Security plugin for WordPress versions 9.0.0 through 9.1.1.1 contains an authentication bypass vulnerability in its two-factor authentication REST API endpoints. The flaw stems from inadequate error handling in the 'check_login_and_get_user' function, which fails to properly validate users during the login process. An unauthenticated attacker can exploit this to gain access as any user account, including administrators, provided that two-factor authentication is enabled in the plugin settings. This vulnerability affects the free, Pro, and Pro Multisite versions of the plugin.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings