CVE · Critical

CVE-2024-10924 — Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] >= 9.0.0 - <= 9.1.1.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10924 Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] >= 9.0.0 - <= 9.1.1.1 Authentication Bypass Using an Alternate Path or Channel Critical 9.8 9.0.0–9.1.2 9.1.2 2024-11-14

CVE-2024-10924

The Really Simple Security plugin for WordPress versions 9.0.0 through 9.1.1.1 contains an authentication bypass vulnerability in its two-factor authentication REST API endpoints. The flaw stems from inadequate error handling in the 'check_login_and_get_user' function, which fails to properly validate users during the login process. An unauthenticated attacker can exploit this to gain access as any user account, including administrators, provided that two-factor authentication is enabled in the plugin settings. This vulnerability affects the free, Pro, and Pro Multisite versions of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.