GHSA-36qh-hpmx-m9cvHighCVSS 7.5
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated...
🔗 CVE IDs covered (1)
📋 Description
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.