Security plugin flaw in millions of WordPress sites gives admin access

Share:

A critical authentication bypass vulnerability has been discovered impacting the WordPress plugin ‘Really Simple Security’ (formerly ‘Really Simple SSL’), including both free and Pro versions.

Really Simple Security is a security plugin for the WordPress platform, offering SSL configuration, login protection, a two-factor authentication layer, and real-time vulnerability detection. Its free version alone is used in over four million websites.

Wordfence, which publicly disclosed the flaw, calls it one of the most severe vulnerabilities reported in its 12-year history, warning that it allows remote attackers to gain full administrative access to impacted sites.

To make matters worse, the flaw can be exploited en masse using automated scripts, potentially leading to large-scale website takeover campaigns.

Such is the risk that Wordfence proposes that hosting providers force-update the plugin on customer sites and scan their databases to ensure nobody runs a vulnerable version.

2FA leading to weaker security
The critical severity flaw in question is CVE-2024-10924, discovered by Wordfence’s researcher István Márton on November 6, 2024.

It is caused by improper handling of user authentication in the plugin’s two-factor REST API actions, enabling unauthorized access to any user account, including administrators.

Specifically, the problem lies in the ‘check_login_and_get_user()’ function that verifies user identities by checking the ‘user_id’ and ‘login_nonce’ parameters.

When ‘login_nonce’ is invalid, the request isn’t rejected, as it should, but instead invokes ‘authenticate_and_redirect(),’ which authenticates the user based on the ‘user_id’ alone, effectively allowing authentication bypass.

The flaw is exploitable when two-factor authentication (2FA) is enabled, and even though it’s disabled by default, many administrators will allow it for stronger account security.

CVE-2024-10924 impacts plugin versions from 9.0.0 and up to 9.1.1.1 of the “free,” “Pro,” and “Pro Multisite” releases.

The developer addressed the flaw by ensuring that the code now correctly handles ‘login_nonce’ verification fails, exiting the ‘check_login_and_get_user()’ function immediately.

The fixes were applied to version 9.1.2 of the plugin, released on November 12 for the Pro version and November 14 for free users.

The vendor coordinated with WordPress.org to perform force security updates on users of the plugin, but website administrators still need to check and ensure they’re running the latest version (9.1.2).

Users of the Pro version have their auto-updates disabled when the license expires, so they must manually update 9.1.2.

As of yesterday, the WordPress.org stats site, which monitors installs of the free version of the plugin, showed approximately 450,000 downloads, leaving 3,500,000 sites potentially exposed to the flaw.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:51 am, Jun 10, 2025
weather icon 14°C
L: 13° | H: 15°
broken clouds
Humidity: 79 %
Pressure: 1016 mb
Wind: 14 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
13° | 15°°C 0.39 mm 39% 11 mph 83 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 23°°C 0 mm 0% 12 mph 82 % 1021 mb 0 mm/h
Thu Jun 12 10:00 pm
weather icon
15° | 24°°C 0.2 mm 20% 11 mph 79 % 1017 mb 0 mm/h
Fri Jun 13 10:00 pm
weather icon
17° | 30°°C 1 mm 100% 12 mph 91 % 1018 mb 0 mm/h
Sat Jun 14 10:00 pm
weather icon
17° | 24°°C 1 mm 100% 11 mph 97 % 1020 mb 0 mm/h
Today 4:00 am
weather icon
14° | 14°°C 0 mm 0% 11 mph 79 % 1016 mb 0 mm/h
Today 7:00 am
weather icon
15° | 15°°C 0 mm 0% 10 mph 81 % 1016 mb 0 mm/h
Today 10:00 am
weather icon
16° | 17°°C 0 mm 0% 11 mph 83 % 1016 mb 0 mm/h
Today 1:00 pm
weather icon
20° | 20°°C 0.39 mm 39% 11 mph 65 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
22° | 22°°C 0.2 mm 20% 10 mph 52 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
20° | 20°°C 0 mm 0% 6 mph 46 % 1019 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 4 mph 61 % 1020 mb 0 mm/h
Tomorrow 1:00 am
weather icon
14° | 14°°C 0 mm 0% 4 mph 78 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€96,182.50
3.97%
Ethereum(ETH)
€2,372.50
8.34%
Tether(USDT)
€0.88
-0.01%
XRP(XRP)
€2.03
2.90%
Solana(SOL)
€140.44
5.28%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.171286
6.82%
Shiba Inu(SHIB)
€0.000011
5.12%
Pepe(PEPE)
€0.000011
9.68%
Peanut the Squirrel(PNUT)
€0.255282
11.91%
Scroll to Top