V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-10924
CVE
CriticalConfirmedExploit available

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 t…

CVSS
9.8
Critical
EPSS
0.82
p99
Published
2024-01-01
Updated
2024-01-01
Description

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

Tags · CWE
Pre-authAuth bypass
CWE-288
CAPEC-127
CAPEC-665
Affected products
Really_simple_security 9.0.0–9.1.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.817 · p99
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-127 · CWE-288
└ via CAPEC-665 · CWE-288
└ via CAPEC-665 · CWE-288
└ via CAPEC-665 · CWE-288
Known exploits — Сканер-ВС
52207
exploitdb · https://www.exploit-db.com/exploits/52207
Enterprise
CVE-2024-10924
github-poc · https://github.com/Trackflaw/CVE-2024-10924-Wordpress-Docker
Enterprise
Affected products
ProductVendorStatus
really_simple_security*Tracked
Source databases
CVE
Related vulnerabilities