
Bypass del MFA en WordPress con el plugin Really Simple Security instalado entre las versiones 9.0.0 – 9.1.1.1.
We access the wordpress website where we will see that it has MFA activated through the vulnerable plugin:

We must execute the PoC and provide the access credentials:

Automatically, the browser will open using a temporary .html file within the administration panel.

To automatically deploy a vulnerable environment to recreate this scenario, you can use the following repository:
https://github.com/Trackflaw/CVE-2024-10924-Wordpress-Docker