CVE-2026-89080 PUBLISHED

Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demotion

Assigner: WPScan
Reserved: 10.09.2026 Published: 13.09.2026 Updated: 13.09.2026

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.

Product Status

Vendor Unknown
Product Really Simple Security
Versions Default: unaffected
  • affected from 9.5.10.1 to 9.8.1 (excl.)

Credits

  • Charles Vosburgh finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE