CVE-2026-89080
massUnauthenticated 2FA Reset Bypass in Really Simple Security WordPress Plugin
The Really Simple Security WordPress plugin before version 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor authentication enrolment, undermining the plugin's own second factor. An attacker who already knows a victim's password can trigger this reset, bypass email 2FA, and log in to obtain that user's session — up to administrator, enabling full site takeover. Any WordPress site running a version below 9.8.1, particularly those relying on the plugin's email-based two-factor authentication, is affected. The flaw carries a high CVSS 3.1 score of 7.5 and is classified as an authentication vulnerability (CWE-287). No public proof of concept exists, the issue is not on CISA's Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.
What to do: Upgrade Really Simple Security to version 9.8.1 or later immediately. Check user accounts for unexpected 2FA enrolment resets and review login/session logs for the vulnerable period, rotating credentials and invalidating sessions for administrator accounts if anything looks off. Because the attack requires prior knowledge of the password, enforce strong unique passwords and consider app-based (TOTP) second factors where available.
| Really Simple Plugins Really Simple Security (WordPress plugin) | before 9.8.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
- Ecosystems
- WordPress
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.