Feed/CVE-2024-10924
CVE-2024-10924CRITICALCVSS 9.8

CVE-2024-10924

Published Nov 14, 2024·Updated Jun 17, 2026

NVD Description

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

Public Exploits & PoCs10 found

PoC: wordpress-cve-2024-10924-exploit

A Proof-of-Concept (PoC) exploit for CVE-2024-10924, a vulnerability in the Really Simple SSL WordPress plugin that allows bypassing two-factor authentication (2FA). Includes mitigation techniques to secure affected WordPress sites.

2

PoC: wordpress-really-simple-security-authn-bypass-vulnerable-application

WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it at your own risk!

2

PoC: 0-click-RCE-Exploit-for-CVE-2024-10924

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security WordPress plugin to impersonate an admin user, upload a malicious plugin, and achieve remote command execution via an interactive shell.

PoC: CVE-2024-10924

CVE-2024-10924 - Authentication Bypass in ReallySimpleSSL Wordpress Plugin

PoC: wordpress-CVE-2024-10924--exploit

WordPress CVE-2024-10924 Exploit for Really Simple Security plugin

PoC: CVE-2024-10924-Exploit

Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass

PoC: CVE-2024-10924

POC for CVE-2024-10924 written in Python

PoC: wordpress-really-simple-security-authn-bypass-exploit

Exploits Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924).

PoC: CVE-2024-10924

Simple Python script

PoC: CVE-2024-10924

Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free