Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
100Vexday Risk Score
Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.
ssvc Actcvss 9.8epss 82%
da publicação à arma0 dias
Publicada no NVD15 de nov.
1ª PoC14 de nov.
metasploit14 de nov.
VulnCheck14 de nov.
probabilidade de exploração
82%top 1% das CVEs
exploração observada
simVulnCheck
39 exploit(s) público(s)
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Really Simple Plugins · Really Simple Security ProReally Simple Plugins · Really Simple Security Pro multisiterogierlankhorst · Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)PoCs públicas encontradas — 39
exploitdbwww.exploit-db.com/exploits/52207não verificadogithubgithub.com/m3ssap0/wordpress-really-simple-security-authn-bypass-exploit★ 19githubgithub.com/JoshuaProvoste/0-click-RCE-Exploit-for-CVE-2024-10924★ 14githubgithub.com/m3ssap0/wordpress-really-simple-security-authn-bypass-vulnerable-application★ 8githubgithub.com/Maalfer/CVE-2024-10924-PoC★ 6githubgithub.com/RandomRobbieBF/CVE-2024-10924★ 4githubgithub.com/D1se0/CVE-2024-10924-Bypass-MFA-Wordpress-LAB★ 4githubgithub.com/ademto/wordpress-cve-2024-10924-pentest★ 3githubgithub.com/Trackflaw/CVE-2024-10924-Wordpress-Docker★ 3githubgithub.com/Nxploited/CVE-2024-10924-Exploit★ 2githubgithub.com/h8sU/wordpress-cve-2024-10924-exploit★ 2githubgithub.com/MaleeshaUdan/wordpress-CVE-2024-10924--exploit★ 1githubgithub.com/d0x-awrqxavc/-CVE-2024-10924★ 0githubgithub.com/julesbsz/CVE-2024-10924★ 0githubgithub.com/sariamubeen/CVE-2024-10924★ 0githubgithub.com/sharafu-sblsec/CVE-2024-10924★ 0githubgithub.com/Hunt3r850/CVE-2024-10924-PoC★ 0githubgithub.com/Hunt3r850/CVE-2024-10924-Wordpress-Docker★ 0githubgithub.com/MattJButler/CVE-2024-10924★ 0githubgithub.com/cy3erdr4g0n/CVE-2024-10924★ 0githubgithub.com/bodoinon/CVE-2024-10924★ 0vulncheckvulncheck.com/xdb/a74366f1cd84não verificadovulncheckvulncheck.com/xdb/1997d266f939não verificadovulncheckvulncheck.com/xdb/8634c35fdcb0não verificadovulncheckvulncheck.com/xdb/76c914e1bdd9não verificadovulncheckvulncheck.com/xdb/13284a68c78anão verificadovulncheckvulncheck.com/xdb/85d4b8964e2anão verificadovulncheckvulncheck.com/xdb/7a0dbe5aa614não verificadovulncheckvulncheck.com/xdb/ae64ddac2bbanão verificadovulncheckvulncheck.com/xdb/7dd188d235denão verificadovulncheckvulncheck.com/xdb/1c53cd3c68d3não verificadovulncheckvulncheck.com/xdb/8bcaff452a99não verificadovulncheckvulncheck.com/xdb/e6fb94b04b8enão verificadovulncheckvulncheck.com/xdb/1d9c43a3144bnão verificadovulncheckvulncheck.com/xdb/8e53b1ad6a94não verificadovulncheckvulncheck.com/xdb/425971f1cc80não verificadovulncheckvulncheck.com/xdb/09e17f47becfnão verificadovulncheckvulncheck.com/xdb/420953eef7a7não verificadovulncheckvulncheck.com/xdb/0663a7f06bf8não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://github.com/JoshuaProvoste/0-click-RCE-Exploit-for-CVE-2024-10924https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L277https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L278https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L67https://plugins.trac.wordpress.org/changeset/3188431/really-simple-sslhttps://www.wordfence.com/blog/2024/11/really-simple-security-vulnerability/https://www.wordfence.com/threat-intel/vulnerabilities/id/7d5d05ad-1a7a-43d2-bbbf-597e975446be?source=cve