Description
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
Published:
2026-09-13
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 13 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. | |
| Title | Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demotion | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-13T06:00:09.950Z
Reserved: 2026-09-10T19:35:57.025Z
Link: CVE-2026-89080
No data.
Status : Received
Published: 2026-09-13T06:16:25.637
Modified: 2026-09-13T06:16:25.637
Link: CVE-2026-89080
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.