really-simple-plugins really_simple_security の CVE(1 件)

CVE 件数: 1 CPE versions: View versions table

概要

本ページは really-simple-plugins really_simple_security に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。

表示中 11 / 1 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2024-10924 The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default). [email protected] 9.8 93.89% 2024-11-15 2026-01-23
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence