Beveiligingsadvies

CVE-2026-89080

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-13 06:00:09
Laatst bijgewerkt 2026-09-13 10:44:06
Toegewezen door WPScan
CVSS-score 7.5
Status PUBLISHED

Beschrijving

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.