Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
wordpress-cve-2024-10924-pentest — Penetration testing report and exploit for CVE-2024-10924, a 2FA bypass in Really Simple SSL, including reconnaissance, exploitation, and remediation guidance. | Kitploit
Tools/GitHubGitHub/ademto/wordpress-cve-2024-10924-pentest
ReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingAuthenticationLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
ademto/wordpress-cve-2024-10924-pentest

wordpress-cve-2024-10924-pentest

Penetration testing report and exploit for CVE-2024-10924, a 2FA bypass in Really Simple SSL, including reconnaissance, exploitation, and remediation guidance.

View Repository
361 year agoNot yet reviewed

WordPress CVE-2024-10924 Penetration Testing Report

2FA Bypass Vulnerability in Really Simple SSL Plugin


📋 Table of Contents

  • Executive Summary
  • Target Information
  • Methodology
  • Timeline
  • Reconnaissance Phase
  • Vulnerability Analysis
  • Attack Flow
  • Exploitation
  • Impact Assessment
  • Remediation
  • Tools Used
  • References
  • Appendices

🎯 Executive Summary

Target: https://skior.co
Vulnerability: CVE-2024-10924 - 2FA Bypass in Really Simple SSL Plugin
Severity: Critical (CVSS Score: 9.8)
Status: Successfully Exploited
Discovery Date: 2025-06-25
Report Version: 2.1

This penetration test discovered a critical authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access to the WordPress site by bypassing two-factor authentication (2FA) controls.

Key Findings

  • ✅ WordPress 6.8.1 with Really Simple SSL plugin installed
  • ✅ 2FA bypass vulnerability successfully exploited
  • ✅ Administrative access obtained for user "pastor"
  • ✅ Valid session cookies captured
  • ✅ Complete control over WordPress administration panel
  • ✅ Zero-day vulnerability (no public exploit available at time of discovery)

Risk Assessment Matrix

Risk LevelProbabilityImpactMitigation Priority
CriticalHighComplete System CompromiseImmediate
HighMediumData BreachHigh
MediumLowService DisruptionMedium

🎯 Target Information

FieldValue
Domainhttps://skior.co
IP Address123.456.789.200
Servernginx/1.26.0 (Ubuntu)
PHP Version8.2.28
CMSWordPress 6.8.1
Vulnerable PluginReally Simple SSL
Geographic LocationUnited States
Hosting ProviderProfessional hosting (likely VPS/Dedicated)

Network Information

  • SSL Certificate: Valid (Let's Encrypt)
  • HTTP/2: Supported
  • Security Headers: Basic implementation
  • CDN: Not detected
  • WAF: Not detected

🔍 Methodology

This assessment followed a systematic black-box penetration testing methodology based on industry standards:

  1. Reconnaissance - Technology identification and passive enumeration
  2. Vulnerability Discovery - Active scanning and manual testing
  3. Exploitation - Proof-of-concept development and execution
  4. Impact Assessment - Evaluation of potential damage
  5. Documentation - Comprehensive reporting and remediation guidance

Testing Approach

  • Black-box testing - No prior knowledge of the target
  • Non-intrusive - Minimal impact on target systems
  • Ethical - Responsible disclosure practices
  • Comprehensive - Multiple attack vectors explored

⏰ Timeline

Date/TimeEventDetails
2025-06-25 14:02Initial ReconnaissanceWappalyzer analysis completed
2025-06-25 14:05Technology Stack IdentifiedWordPress 6.8.1, nginx, PHP 8.2.28
2025-06-25 14:10User EnumerationDiscovered user "pastor" (ID: 1)
2025-06-25 14:15WPScan AnalysisNo known vulnerabilities found
2025-06-25 14:20REST API EnumerationDiscovered Really Simple SSL endpoints
2025-06-25 14:25Vulnerability ResearchIdentified CVE-2024-10924
2025-06-25 14:30Manual TestingConfirmed vulnerability existence
2025-06-25 14:35Exploit DevelopmentCreated Python proof-of-concept
2025-06-25 14:40Successful ExploitationObtained admin access
2025-06-25 14:45Impact AssessmentDocumented potential damage
2025-06-25 15:00Report GenerationComprehensive documentation

🔎 Reconnaissance Phase

Step 1: Technology Stack Identification

A. Wappalyzer Analysis

Wappalyzer Results

Identified Technologies:

  • WordPress 6.8.1 (Latest version)
  • Elementor 3.29.2 (Page builder)
  • Astra Theme 4.11.3
  • PHP 8.2.28
  • nginx 1.26.0 (Ubuntu)
  • jQuery 3.7.1

B. WhatWeb Deep Scan

└─$ whatweb https://skior.co
https://skior.co [200 OK] Country[UNITED STATES][US], HTML5, \
HTTPServer[Ubuntu Linux][nginx/1.26.0 (Ubuntu)], IP[123.456.789.200], \
JQuery[3.7.1],MetaGenerator[Elementor 3.29.2; \
features: additional_custom_breakpoints, e_local_google_fonts; \
settings: css_print_method-external, google_font-enabled, font_display-swap,\
WordPress 6.8.1], PHP[8.2.28], PoweredBy[Skior], \
Script[speculationrules,text/javascript], Title[Skior Technologies], \
UncommonHeaders[link], WordPress[6.8.1], X-Powered-By[PHP/8.2.28], nginx[1.26.0]

Key Findings:

  • Modern WordPress installation with latest version
  • Professional hosting setup with nginx
  • Custom branding ("PoweredBy[Skior]")
  • Elementor page builder in use
  • Geographic location: United States

Step 2: User Enumeration

A. WordPress Author Enumeration

└─$ curl -I https://skior.co/?author=1
HTTP/1.1 301 Moved Permanently
Server: nginx/1.26.0 (Ubuntu)
Date: Wed, 25 Jun 2025 18:12:15 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
X-Powered-By: PHP/8.2.28
X-Redirect-By: WordPress
Location: https://skior.co/author/pastor/

Discovered User: pastor (User ID: 1)

B. Additional User Enumeration Techniques

# Check for multiple users
for i in {1..10}; do
    echo "Checking user ID: $i"
    curl -s -o /dev/null -w "%{http_code}" "https://skior.co/?author=$i"
    echo " - https://skior.co/?author=$i"
done

C. Username Enumeration Results

User IDUsernameStatusRedirect URL
1pastor✅ Found/author/pastor/
2-10N/A❌ Not Found404 responses

Step 3: Vulnerability Scanning

A. WPScan Comprehensive Analysis

└─$ wpscan --url https://skior.co --api-token my-api-key

Scan Results Summary:

  • ✅ WordPress 6.8.1 (Latest, released 2025-04-30)
  • ✅ Theme: Astra 4.11.3 (Up to date)
  • ✅ Plugins identified:
    • Elementor 3.29.2
    • Astra Sites 4.4.26
    • Header Footer Elementor 2.4.2
    • WPForms Lite 1.9.6.1
  • ⚠️ XML-RPC enabled (potential attack vector)
  • ⚠️ External WP-Cron enabled
  • ❌ No known vulnerabilities found in scanned components

Note: WPScan did not detect the Really Simple SSL plugin, indicating it may be using obfuscation or custom naming.

B. REST API Enumeration

└─$ curl -s https://skior.co/wp-json/ | jq '.routes | keys[]'

Discovered Custom Endpoints:

/reallysimplessl/v1/two_fa
/reallysimplessl/v1/two_fa/skip_onboarding
/reallysimplessl/v1/two_fa/do_not_ask_again
/reallysimplessl/v1/two_fa/resend_email_code
/reallysimplessl/v1/two_fa/save_default_method_email
/reallysimplessl/v1/two_fa/save_default_method_email_profile
/reallysimplessl/v1/two_fa/save_default_method_totp
/reallysimplessl/v1/two_fa/validate_email_setup

Critical Discovery: The /reallysimplessl/v1/two_fa/skip_onboarding endpoint appeared suspicious and warranted further investigation.


🔬 Vulnerability Analysis

CVE-2024-10924 Research

After discovering the custom REST API routes, external research revealed CVE-2024-10924, a critical vulnerability affecting the Really Simple SSL plugin.

Vulnerability Details

CVE ID: CVE-2024-10924
CVSS Score: 9.8 (Critical)
Affected Plugin: Really Simple SSL
Vulnerability Type: Authentication Bypass
Attack Vector: REST API
Discovery Date: November 6, 2024
Public Disclosure: November 14, 2024

Download Tool