logo

Critical WordPress Plug-in Flaw Exposes 4M Sites to Takeover

ID: 3a9e8d22-06ba-5260-8eec-77f032d01489

STIX ID: report--3a9e8d22-06ba-5260-8eec-77f032d01489

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-11-18

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

A critical authentication-bypass vulnerability (CVSS 9.8) was discovered in the Really Simple Security WordPress plugin (v9.0.0–9.1.1.1) that improperly handles 2FA REST API checks, allowing attackers to bypass authentication and gain administrative access; the flaw is scriptable and could be used for large-scale automated attacks against millions of sites, and although a patch (9.1.2) and forced updates were issued, some sites (notably those without valid licenses) may remain vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.