← All CVEs

CVE-2024-10924

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

9.8
CVSS
82.0%
EPSS (exploit prob.)
100th
EPSS percentile
2024-11-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-288CWE-306

Affected products

VendorProductAffected versions
really-simple-pluginsreally_simple_security>= 9.0.0, < 9.1.2
really-simple-pluginsreally_simple_security>= 9.0.0, < 9.1.2
really-simple-pluginsreally_simple_security>= 9.0.0, < 9.1.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-10924