CVE-2026-82519
Received Received - Intake

Really Simple Security WordPress Plugin Missing Authorization Check Bypasses 2FA

Vulnerability report for CVE-2026-82519, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a crafted POST request without the two-factor-authentication field to skip nonce verification and trigger delete_two_fa_meta(), which resets the grace period anchor timestamp on every login cycle, causing mandatory 2FA enforcement to be deferred indefinitely.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
really_simple_security plugin to 9.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Really Simple Security plugin for WordPress before version 9.8.2. It allows low-privileged authenticated attackers to bypass two-factor authentication (2FA) indefinitely by exploiting a missing authorization check in the profile-page update handler. Attackers can send a crafted POST request to reset the 2FA grace period, causing mandatory 2FA enforcement to be deferred permanently.

Impact Analysis

If you use the Really Simple Security plugin before version 9.8.2, attackers with low-level access could bypass your two-factor authentication. This means they could gain unauthorized access to your WordPress account even if 2FA is enabled, potentially leading to data theft, unauthorized changes, or further compromise of your site.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized access to sensitive data, which violates principles of data protection in regulations like GDPR and HIPAA. Organizations using the vulnerable plugin may fail to meet requirements for strong authentication and access controls, risking legal penalties and reputational damage.

Mitigation Strategies

Update the Really Simple Security plugin for WordPress to version 9.8.2 or later to address the missing authorization check vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82519. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart