Really Simple Security Pro <= 9.5.4.0 - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The Really Simple Security Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.5.4.0 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized a...
- CVSS:
- 4.3
- Affected:
- up to 9.5.4.0
- Fixed in:
- 9.5.4.1
- Disclosed:
- Feb 23, 2026
CVE-2026-27397 on NVD →
Really Simple Security Pro [really-simple-ssl-pro] >= 9.0.0 - <= 9.1.1.1
unknown
[en] The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthe...
- Affected:
- 9.0.0 – 9.1.1.1
- Fixed in:
- 9.1.1.1
- Disclosed:
- Nov 15, 2024
CVE-2024-10924 on NVD →
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
critical
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthentica...
- CVSS:
- 9.8
- Affected:
- 9.0.0 – 9.1.1.1
- Fixed in:
- 9.1.2
- Disclosed:
- Nov 14, 2024
CVE-2024-10924 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database