Sat, October 10, 2026

CVE-2024-10924: Is Your WordPress Site Protected?

CVE-2024-10924: Is Your WordPress Site Protected?

CVE-2024-10924 is a critical authentication bypass vulnerability (CVSS 9.8) found in the Really Simple Security plugin for WordPress. Affecting versions 9.0.0 through 9.1.1.1, the flaw allows unauthenticated attackers to gain full administrative access by exploiting the plugin's REST API endpoints.

You are only affected if you are still on one of those vulnerable versions, and the fix is to update to 9.1.2 or later. The rest of this guide covers how the bypass works, how to check your plugin version, the steps to patch it, and what to verify afterward so your 2FA setup still holds.

Understanding the Authentication Bypass Risk

The vulnerability stems from improper error handling within the 'check_login_and_get_user' function of the two-factor authentication REST API. When 2FA is active, these endpoints fail to validate user identity, rendering the login process bypassable.

How the vulnerability works

The plugin's two-factor authentication setup relies on REST API endpoints to handle verification steps. In the affected versions, these endpoints did not enforce proper authentication checks before processing requests.

An attacker could send a crafted request to bypass the login process entirely. This does not require stealing passwords or exploiting SQL injection; it simply exploits missing permission logic in the API layer.

Why 2FA settings matter

Two-factor authentication is your second line of defense when passwords fail. It assumes that even if one factor is compromised, the other will block entry.

This vulnerability breaks that assumption by rendering the second factor optional. Attackers can skip 2FA altogether, meaning a strong password or hardware key offers no protection against this specific exploit.

If you have enabled 2FA through Really Simple Security and remain on an affected version, that security layer is effectively disabled for anyone who knows how to query the API correctly.

Identifying Affected Plugin Versions

Identifying Affected Plugin Versions

Version 9.1.2, released on 12 November 2024, is the exact release that patched this flaw.

Scope of the vulnerability

The bug affected both the Free and Pro editions of Really Simple Security.

  • Vulnerable versions: 9.0.0 through 9.1.1.1.
  • Patched version: 9.1.2 and all subsequent releases.
  • The defect targeted the plugin's two-factor authentication REST API endpoints.

Checking your current version

Navigate to Plugins > Installed Plugins in your WordPress dashboard and locate the Really Simple Security row.

The active version number appears directly beneath the plugin name.

  • If it reads 9.0.0 to 9.1.1.1, your site is currently vulnerable and requires an immediate update to at least version 9.1.2.
  • If it reads 9.1.2 or higher, this specific authentication bypass is already resolved.
Steps to Secure Your Installation

Steps to Secure Your Installation

While version 9.1.2 provides the initial patch for this flaw, you should update to the most recent stable release to address subsequent security vulnerabilities.

Updating to the latest release

Find Really Simple Security in the list and check the current version number against 9.1.2. If it is older, click Update now.

  • Version 9.1.2 contains the specific fix for CVE-2024-10924.
  • The latest stable release is currently 9.8.3, which includes additional security improvements.
  • If an update option does not appear, delete the plugin and re-upload the latest zip file from the official source.

This process applies equally to both Free and Pro editions of the plugin.

Verifying security configuration

A successful update does not automatically configure every protection feature correctly. You must confirm that two-factor authentication remains active for all administrator accounts after the patch is applied.

  • Log in to your site using a different browser or incognito window to test access controls.
  • Verify that your email-based 2FA setup still triggers correctly during login attempts.
  • If you use Pro features like country blocking or firewall rules, ensure they are still enabled in settings.

Treat any unexpected access prompts or disabled security toggles as a red flag requiring immediate investigation before you close out this maintenance task.

FAQ

Does CVE-2024-10924 affect sites that have not enabled two-factor authentication?

No, the vulnerability is only exploitable if the "Two-Factor Authentication" setting is active in your plugin configuration. The NVD record explicitly notes that this flaw is present when that specific setting is enabled, which is disabled by default for new installations. If you have never turned on 2FA through Really Simple Security, this particular authentication bypass does not apply to your site.

Which specific function contains the error handling flaw described in the CVE?

The defect resides in the 'check_login_and_get_user' function within the plugin's two-factor REST API actions. This function failed to properly verify user identity before processing requests, allowing an attacker to bypass login checks entirely. Understanding this helps you confirm that the issue was strictly a logic error in permission verification rather than a data injection or memory corruption problem.

Does updating to version 9.1.2 fully protect against all current security issues in Really Simple Security?

No, version 9.1.2 only patches CVE-2024-10924 and leaves your site vulnerable to newer flaws discovered after November 2024. For example, versions prior to 9.8.1 are affected by CVE-2026-89080, which was fixed in release 9.8.1 on September 13, 2026. Since the latest stable release is now 9.8.3, you should update directly to that version rather than stopping at the initial patch for this specific bypass.

Share this article
Contents
  1. Understanding the Authentication Bypass Risk
  2. How the vulnerability works
  3. Why 2FA settings matter
  4. Identifying Affected Plugin Versions
  5. Scope of the vulnerability
  6. Checking your current version
  7. Steps to Secure Your Installation
  8. Updating to the latest release
  9. Verifying security configuration
  10. FAQ
  11. Does CVE-2024-10924 affect sites that have not enabled two-factor authentication?
  12. Which specific function contains the error handling flaw described in the CVE?
  13. Does updating to version 9.1.2 fully protect against all current security issues in Really Simple Security?