Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 13 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Sun, 13 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. | |
| Title | Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demotion | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-13T10:44:06.593Z
Reserved: 2026-09-10T19:35:57.025Z
Link: CVE-2026-89080
Updated: 2026-09-13T10:41:19.967Z
Status : Received
Published: 2026-09-13T06:16:25.637
Modified: 2026-09-13T11:16:59.650
Link: CVE-2026-89080
No data.
OpenCVE Enrichment
No data.