HIGH
CVE-2026-89080
CVSS
7.5
Description
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
Weakness (CWE)
CWE-287
Improper Authentication
EPSS Score
0.2%
Probability of exploitation in next 30 days
10.5th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.