Description
Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a crafted POST request without the two-factor-authentication field to skip nonce verification and trigger delete_two_fa_meta(), which resets the grace period anchor timestamp on every login cycle, causing mandatory 2FA enforcement to be deferred indefinitely.
Published: 2026-09-14
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass: deferred 2FA enforcement
Action: Assess Impact
AI Analysis

Impact

The Really Simple authorization check that lets submitting a specially crafted POST request to the profile‑page update handler, attackers can skip nonce verification and invoke delete_two_fa_meta(), resetting the grace‑period anchor timestamp. This logic flaw, identified as CWE‑862, allows the 2FA requirement to be deferred indefinitely, weakening the authentication barrier without any elevated privileges.

Affected Systems

All installations of the Really Simple Security WordPress plugin with a version earlier than 9.8.2 are impacted. This includes any site using the plugin before the 9.8.2 release, regardless of hosting environment, as the vulnerability resides in the plugin code itself.

Risk and Exploitability

The CVSS score is 2.3, indicating a low overall severity. Since the EPSS score is < 1% and the issue is not listed in the CISA KEV catalog, the probability of widespread exploitation is low. Nonetheless, authenticated users that do not possess higher privileges could exploit the unguarded path by targeting the profile‑page update endpoint. The attack requires knowledge of the plugin’s parameter names and the ability to send a POST request, conditions that are typically satisfied by any logged‑in user with read‑write access to their own profile.

Generated by OpenCVE AI on September 20, 2026 at 23:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Really Simple Security plugin to version 9.8.2 or later to apply the missing authorization check fix.
  • If an immediate upgrade is not possible, block the profile‑page update handler for low‑priv‑based access control or a security plugin.
  • Review WordPress audit logs for unexpected POST requests to the profile‑page update endpoint and investigate any unauthorized activity.

Generated by OpenCVE AI on September 20, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Really-simple-plugins
Really-simple-plugins really Simple Security
Wordpress
Wordpress wordpress
Vendors & Products Really-simple-plugins
Really-simple-plugins really Simple Security
Wordpress
Wordpress wordpress

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a crafted POST request without the two-factor-authentication field to skip nonce verification and trigger delete_two_fa_meta(), which resets the grace period anchor timestamp on every login cycle, causing mandatory 2FA enforcement to be deferred indefinitely.
Title Really Simple Security < 9.8.2 Authorization Bypass via profile-page update handler
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Really-simple-plugins Really Simple Security
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T00:35:30.689Z

Reserved: 2026-08-29T17:20:57.081Z

Link: CVE-2026-82519

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:41.468Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T19:17:51.183

Modified: 2026-09-20T01:16:30.320

Link: CVE-2026-82519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses