Impact
An unauthenticated request can reset a user’s completed email two‑factor enrolment, allowing an attacker who already knows the account’s password to bypass the second factor privileges.
Affected Systems
The Really Simple Security WordPress plugin versions earlier than 9.8.1 are impacted; any installation using those releases allows this behaviour.
Risk and Exploitability
The vulnerability admits unauthenticated exploitation through standard HTTP requests. The EPSS score is less than 1%, indicating a very low exploitation probability, and the issue is not listed in the CISA KEV catalog, but its impact consists of privilege escalation and loss of account integrity. The CVSS score of 7.5 indicates high severity. Attackers request to any site using the affected plugin.
OpenCVE Enrichment