CVE-2026-82519: Really Simple Security < 9.8.2 Authorization Bypass via profile-page update handler

Published Sep 14, 2026
·
Updated

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a crafted POST request without the two-factor-authentication field to skip nonce verification and trigger deletetwofameta(), which resets the grace period anchor timestamp on every login cycle, causing mandatory 2FA enforcement to be deferred indefinitely.

Affected Software

1 affected component
Really Simple Security<9.8.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Really Simple Security (WordPress) to a version that resolves this vulnerability.

    Fixed in 9.8.2
  2. Compensating control

    Apply compensating access control by restricting who can access the Really Simple Security profile-page update handler so low-privileged authenticated users cannot reach the missing authorization check code path until the plugin is upgraded to 9.8.2.

Event History

Sep 14, 2026
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must already be authenticated with a low-privileged account. The attack can be performed remotely and does not require user interaction.

2

What does an attacker need to do to bypass 2FA enforcement?

They need to submit a crafted POST request to the profile-page update handler that omits the two-factor-authentication field. This follows an unguarded path that skips nonce verification and resets the 2FA grace-period anchor timestamp.

3

What is the practical impact on affected accounts?

Mandatory two-factor authentication can be deferred indefinitely for the attacking authenticated account. The attacker can reset the grace-period timing on each login cycle rather than completing enforced 2FA.

4

Which versions are affected?

Really Simple Security versions before 9.8.2 are affected. Updating to version 9.8.2 or later addresses the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203