Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82519— Really Simple Security < 9.8.2 Authorization Bypass via profile-page update handler

Quick assessment

Affected
reallysimpleplugins Really Simple Security
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Really Simple Security 插件在 9.8.2 版本之前存在一个“缺少授权检查”的漏洞。该漏洞允许经过认证的、低权限的攻击者通过利用个人资料页面更新处理程序中一条未加保护的代码路径,无限期地绕过强制的二因素身份验证(2FA)。 具体来说,攻击者可以构造一个未包含二因素身份验证字段的 POST 请求,从而跳过 nonce 验证并触发 函数。该函数会在每次登录周期中重置宽限期的锚点时间戳,导致强制 2FA 的执行被无限期推迟。

CVSS 4.3 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
reallysimpleplugins Really Simple Security < 9.8.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82519

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Really Simple Security < 9.8.2 Authorization Bypass via profile-page update handler
Source: CVE Program / CVE List V5
Vulnerability Description
Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a crafted POST request without the two-factor-authentication field to skip nonce verification and trigger delete_two_fa_meta(), which resets the grace period anchor timestamp on every login cycle, causing mandatory 2FA enforcement to be deferred indefinitely.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
reallysimpleplugins Really Simple Security 0 ~ 9.8.2 -

II. Public POCs for CVE-2026-82519

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82519

登录查看更多情报信息。

Vendor Advisories for CVE-2026-82519 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-82519

No comments yet


Leave a comment