LOW
reallysimpleplugins
CVE published 2026-09-14
CVE-2026-82519
The Really Simple Security plugin for WordPress before version 9.8.2 contains a missing authorization check vulnerability. This allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. The vulnerability impacts WordPress sites using the Really Simple Security plugin, as defenders must ve [truncated]