← Back to browse · API

CVE-2024-10924

Severity
CRITICAL
CVSS
9.8
EPSS
0.81722
Risk score
67.8
CISA KEV
No
PoC
No
Published
2024-11-15
Modified
2026-01-23
First seen
2026-08-07
Aliases
EUVD-2024-33353, GHSA-F75H-CWP9-8H5X
Products
Really Simple Plugins B.V.:Really Simple Security Pro 9.0.0 ≤9.1.1.1, Really Simple Plugins:Really Simple Security Pro multisite 9.0.0 ≤9.1.1.1, rogierlankhorst:Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) 9.0.0 ≤9.1.1.1
Sources
euvd EUVD-2024-33353

Description

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

References