CVE-2024-10924General(really-simple-plugins / really_simple_security)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch really-simple-plugins really_simple_security systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • really_simple_security

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-01-28); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Products
really_simple_security

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-01-28: 1Mentions · 2026-03-04: 1Mentions · 2026-03-06: 1Mentions · 2026-05-06: 1Mentions · 2026-05-16: 1PoC Mentioned / Linked · 2026-03-04: 1Exploit Tool / Code · 2026-03-04: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-01-28: 1Technical Details · 2026-03-04: 101-2803-0403-0605-0605-16
Signal classification4 categories
General
240.0%
Disclosure
120.0%
Active Exploitation
120.0%
PoC
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-03-041
Active Exploitation1
2026-03-061
General1
2026-05-061
General1
2026-05-161
PoC1
Full discourse5 posts
  • WPSec - WordPress Security Scanner@WPSecScanner
    Disclosure

    The Full Story of CVE-2024-10924: Authentication Bypass in the Really Simple Security Plugin: https://blog.wpsec.com/the-full-story-of-cve-2024-10924-authentication-bypass-in-the-really-simple-security-plugin/ #WordPressSecurity #WordPress #AuthenticationBypass #SecurityAlert #Cybersecurity #Infosec #PluginVulnerability #UpdateNow #PatchNow #WebSecurity #WPPlugins #SiteSecurity

    Post summary

    The blog post provides a detailed disclosure of CVE-2024‑10924, describing an authentication bypass in the Really Simple Security plugin, but does not mention active exploitation, patches, or a PoC.

    00031190
    8.0K followersView on X
  • jp / kw0@JoshuaProvoste
    Active Exploitation

    1️⃣ 0-click RCE Exploit for CVE-2024-10924 affecting over 4 million WordPress sites ⚙️ https://lnkd.in/dw__Mf3W 2️⃣ Unauthenticated Stored Cross-Site Scripting (XSS) for CVE-2026-2472 affecting the Google Cloud Vertex AI SDK ⚙️ https://lnkd.in/dR_2xKnD

    Post summary

    The tweet announces active exploitation of CVE-2024-10924 via a 0‑click RCE affecting millions of WordPress sites and a stored XSS in CVE-2026-2472 targeting Google Cloud Vertex AI SDK, with links to further details but no patch information.

    1001092
    2.8K followersView on X
  • Himadri Singh@LittleSun4lower
    General

    I just completed Bypass Really Simple Security room on TryHackMe! Learn how to exploit a WordPress website using CVE-2024-10924 and understand various mitigation techniques. https://tryhackme.com/room/bypassreallysimplesecurity?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #Consistency

    Post summary

    The tweet promotes a TryHackMe room that teaches exploitation of CVE-2024-10924 on a WordPress site, offering mitigation insights but lacking explicit PoC, exploit code, or patch details.

    0001053
    8 followersView on X
  • Cx$xMaDD@Christe05505504
    PoC

    I just completed Bypass Really Simple Security room on TryHackMe! Learn how to exploit a WordPress website using CVE-2024-10924 and understand various mitigation techniques. #Labeveryday #DefensiveSecurity #SOCAnalyst #Homelabs https://tryhackme.com/room/bypassreallysimplesecurity?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=6029a238f1ad981629dd879a #tryhackme via @tryhackme

    Post summary

    The tweet highlights completion of a TryHackMe room that teaches exploitation of CVE‑2024‑10924 on WordPress and discusses mitigation, but does not provide PoC code or evidence of active attacks.

    0000073
    1.3K followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed Bypass Really Simple Security room on TryHackMe! Learn how to exploit a WordPress website using CVE-2024-10924 and understand various mitigation techniques. https://tryhackme.com/room/bypassreallysimplesecurity?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The tweet references CVE-2024-10924 in the context of a TryHackMe training room, but it does not provide any technical details, PoC, exploit code, or active exploitation evidence.

    0000051
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appreally-simple-pluginsreally_simple_security-wordpress-
Appreally-simple-pluginsreally_simple_security-wordpress-
Appreally-simple-pluginsreally_simple_security-wordpress-

Explore more