
Proof-of-concept exploit for CVE-2024-10924, an authentication bypass vulnerability in the Really Simple Security WordPress plugin, enabling MFA bypass via crafted requests.
We access the WordPress web page where we will see that it has MFA enabled through the vulnerable plugin:

We must run the PoC and provide the login credentials:

Automatically, the browser will open via a temporary .html file within the administration panel.

To automatically deploy a vulnerable environment to recreate this scenario, you can use the following repository:
https://github.com/Trackflaw/CVE-2024-10924-Wordpress-Docker