logo

Security plugin flaw in millions of WordPress sites gives admin access

ID: 6230a1e0-94b7-5085-a956-2d6f3759ac40

STIX ID: report--6230a1e0-94b7-5085-a956-2d6f3759ac40

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-11-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

- A critical authentication bypass (CVE-2024-10924) in the WordPress plugin Really Simple Security allows attackers to bypass 2FA and gain administrative access on affected sites (versions 9.0.0–9.1.1.1); fixes were released in 9.1.2 and hosting providers/administrators are urged to update immediately, as millions of sites could be exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.