CVE-2024-10924

Published Nov 15, 2024

Last updated 2 days ago

Insights

Analysis from the Intruder Security Team
Published Nov 15, 2024

This is a wormable vulnerability that is very easy to exploit and we expect imminent and automated exploitation of this vulnerability.

As for the pre-requisites, for the explioit to work no user of the application needs to have "Two Factor Authentication" (2FA) enabled within Really SImple Security. As soon as the 2FA feature is enabled, an unauthenticated attacker can make a request to the vulnerable function and WordPress will return a valid session token for the victim.

A partial proof of concept has been released which does not work out of the box. However, due to how simple this vulnerability is, it requires little effort to get it working.

Overview

Description
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).
Source
security@wordfence.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-288

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. به تازگی آسیب پذیری با کد شناسایی CVE-2024-10924 برای پلاگین معروف Wordpress به نام Really Simple Security منتشر شده است که ۴ میلیون وب سایت wordpress در معرض هک شدن در سراسر دنیا می باشند. نسخه های 9.0.0 تا 9.1.1.1 این پلاگین دارای این آسیب پذیری می باشد. https://t.co/Poz3aKY03t

    @AmirHossein_sec

    17 Nov 2024

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. #WordPress Over 4mln WordPress websites were impacted by a critical 'Really Simple Security' plugin authentication bypass vulnerability CVE-2024-10924 (CVSS score 9.8) exposing websites to takeover and providing full administrative access: 👇 https://t.co/EX9Wdwveir https://t.co

    @securestep9

    16 Nov 2024

    68 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. Critical security vulnerability CVE-2024-10924 in WordPress Really Simple Security plugin affects 4M+ websites. Patch available in version 9.1.2. More details here: https://t.co/AhVs5SuVMF #WordPress #ReallySimpleSecurity #Vulnerability

    @CandidTodayTech

    15 Nov 2024

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2024-10924 The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to i… https://t.co/q4lohITdci

    @CVEnew

    15 Nov 2024

    513 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-10924 (CVSS 9.8): Authentication Bypass in Really Simple Security Plugin Affects 4 Million Sites https://t.co/OlvSLmOPpl

    @Dinosn

    15 Nov 2024

    2473 Impressions

    11 Retweets

    18 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  6. After almost a year, here’s another blog post about a vulnerable plugin (CVE-2024-10924): https://t.co/fdQH8ELE54 #WordPressPlugins #PatchNow

    @the_pesc

    14 Nov 2024

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. 【無要素認証】400万サイトが使用しているWordPressのReally Simple Securityプラグインに重大(Critical)な認証回避の脆弱性。FreeとPro双方に影響。CVE-2024-10924はCVSSスコア9.8。nonceエラーを起こすと二要素認証機能が通過した扱いとなりIDだけでログイン可能。https://t.co/fquH4J9oSF https://t.co/imXn1mbcgI

    @__kokumoto

    14 Nov 2024

    2184 Impressions

    11 Retweets

    14 Likes

    6 Bookmarks

    0 Replies

    2 Quotes