« Volver al listado

Really-simple-plugins

Really-simple-plugins Really Simple Security: vulnerabilidades y CVE

Really-simple-plugins Really Simple Security tiene 6 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses5
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-88798Media (5.3)0.42%—18 sept 2026
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that…
CVE-2026-82519Baja (2.3)0.36%—14 sept 2026
Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely…
CVE-2026-89080Alta (7.5)0.34%—13 sept 2026
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's…
CVE-2026-81766Media (6.6)0.43%—30 ago 2026
The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing…
CVE-2026-8293Alta (7.5)0.39%—2 jun 2026
The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain…
CVE-2024-10924Crítica (9.8)82%—15 nov 2024
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts1
  2. T1190 Exploit Public-Facing Application1
  3. T1210 Exploitation of Remote Services1
  4. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Really-simple-plugins