WordPress Plugin Vulnerabilities

Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demotion

Description

The plugin does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.

Proof of Concept

Affects Plugins

Fixed in 9.8.1

References

Classification

Miscellaneous

Original Researcher
Charles Vosburgh
Submitter
Charles Vosburgh
Verified
Yes

Timeline

Publicly Published
2026-09-11 (about 2 days ago)
Added
2026-09-11 (about 1 day ago)
Last Updated
2026-09-11 (about 1 day ago)

Other