PT-2026-91411 · Really Simple Plugins · Really Simple Security
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Really Simple Security plugin for WordPress versions prior to 9.8.2
Description
An authorization check is missing in the profile-page update handler, allowing authenticated low-privileged attackers to bypass enforced two-factor authentication (2FA) indefinitely. By submitting a crafted POST request that omits the
two-factor-authentication field, an attacker can skip nonce verification and trigger the delete two fa meta() function. This action resets the grace period anchor timestamp during every login cycle, which defers the mandatory 2FA enforcement.Recommendations
Update Really Simple Security plugin for WordPress to version 9.8.2 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Really Simple Security