PT-2026-91411 · Really Simple Plugins · Really Simple Security

·

CVE-2026-82519

·

Published

2026-09-14

·

Updated

2026-09-20

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Really Simple Security plugin for WordPress versions prior to 9.8.2
Description An authorization check is missing in the profile-page update handler, allowing authenticated low-privileged attackers to bypass enforced two-factor authentication (2FA) indefinitely. By submitting a crafted POST request that omits the two-factor-authentication field, an attacker can skip nonce verification and trigger the delete two fa meta() function. This action resets the grace period anchor timestamp during every login cycle, which defers the mandatory 2FA enforcement.
Recommendations Update Really Simple Security plugin for WordPress to version 9.8.2 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82519

Affected Products

Really Simple Security