Impact
The Really Simple authorization check that lets submitting a specially crafted POST request to the profile‑page update handler, attackers can skip nonce verification and invoke delete_two_fa_meta(), resetting the grace‑period anchor timestamp. This logic flaw, identified as CWE‑862, allows the 2FA requirement to be deferred indefinitely, weakening the authentication barrier without any elevated privileges.
Affected Systems
All installations of the Really Simple Security WordPress plugin with a version earlier than 9.8.2 are impacted. This includes any site using the plugin before the 9.8.2 release, regardless of hosting environment, as the vulnerability resides in the plugin code itself.
Risk and Exploitability
The CVSS score is 2.3, indicating a low overall severity. Since the EPSS score is < 1% and the issue is not listed in the CISA KEV catalog, the probability of widespread exploitation is low. Nonetheless, authenticated users that do not possess higher privileges could exploit the unguarded path by targeting the profile‑page update endpoint. The attack requires knowledge of the plugin’s parameter names and the ability to send a POST request, conditions that are typically satisfied by any logged‑in user with read‑write access to their own profile.
OpenCVE Enrichment