Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-10924

Опубликовано: 15 нояб. 2024
Источник: nvd
CVSS3: 9.8
EPSS Критический

Описание

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:really-simple-plugins:really_simple_security:*:*:*:*:-:wordpress:*:*
Версия от 9.0.0 (включая) до 9.1.2 (исключая)
cpe:2.3:a:really-simple-plugins:really_simple_security:*:*:*:*:pro:wordpress:*:*
Версия от 9.0.0 (включая) до 9.1.2 (исключая)
cpe:2.3:a:really-simple-plugins:really_simple_security:*:*:*:*:pro_multisite:wordpress:*:*
Версия от 9.0.0 (включая) до 9.1.2 (исключая)

EPSS

Процентиль: 100%
0.93799
Критический

9.8 Critical

CVSS3

Дефекты

CWE-288
CWE-306

Связанные уязвимости

CVSS3: 9.8
github
около 1 года назад

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

CVSS3: 9.8
fstec
больше 1 года назад

Уязвимость плагинов Really Simple Security Free, Really Simple Security Pro и Really Simple Security Pro Multisite системы управления содержимым сайта WordPress, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 100%
0.93799
Критический

9.8 Critical

CVSS3

Дефекты

CWE-288
CWE-306