CVE-2026-89080
Received Received - Intake

Two-Factor Authentication Bypass in Really Simple Security WordPress Plugin

Vulnerability report for CVE-2026-89080, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-13

Last updated on: 2026-09-13

Assigner: WPScan

Description

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-13
Last Modified
2026-09-13
Generated
2026-09-13
AI Q&A
2026-09-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
really_simple_security plugin to 9.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Really Simple Security WordPress plugin before version 9.8.1 has a flaw where an unauthenticated attacker can reset a user's completed email-based two-factor authentication (2FA) enrollment. This allows someone who knows the user's password to bypass the 2FA and gain access to the user's session, potentially escalating privileges to administrator level.

Detection Guidance

To detect this vulnerability, check the version of the Really Simple Security WordPress plugin. If it is below 9.8.1, the system is vulnerable. No specific commands are provided in the context, but inspecting plugin files or using WordPress admin panels for version checks is recommended.

Impact Analysis

If you use the Really Simple Security plugin before version 9.8.1, an attacker who knows your password could bypass your 2FA and gain unauthorized access to your WordPress account. This could lead to data theft, unauthorized changes, or full control of your site if they escalate to administrator privileges.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR or HIPAA. Organizations using the vulnerable plugin may face legal and regulatory penalties due to potential data breaches or unauthorized access to protected information.

Mitigation Strategies

Update the Really Simple Security WordPress plugin to version 9.8.1 or later to prevent the vulnerability from being exploited.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89080. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart