Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Really-simple-plugins
Really-simple-plugins really Simple Security Wordpress Wordpress wordpress |
|
| Vendors & Products |
Really-simple-plugins
Really-simple-plugins really Simple Security Wordpress Wordpress wordpress |
Tue, 02 Jun 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Tue, 02 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Tue, 02 Jun 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Tue, 02 Jun 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge. | |
| Title | Really Simple Security < 9.5.10.1 - Authentication Bypass via Two-Factor OTP Skip | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-06-02T10:39:15.547Z
Reserved: 2026-05-11T08:12:42.273Z
Link: CVE-2026-8293
Updated: 2026-06-02T10:39:03.715Z
Status : Deferred
Published: 2026-06-02T07:16:13.707
Modified: 2026-06-02T14:43:49.920
Link: CVE-2026-8293
No data.
OpenCVE Enrichment
Updated: 2026-06-02T15:30:11Z