Wednesday, May 14, 2025
HomeCVE/vulnerability4M+ WordPress Websites to Attacks, Following Plugin Vulnerability

4M+ WordPress Websites to Attacks, Following Plugin Vulnerability

Published on

SIEM as a Service

Follow Us on Google News

A critical vulnerability has been discovered in the popular “Really Simple Security” WordPress plugin, formerly known as “Really Simple SSL,” putting over 4 million websites at risk.

The flaw, identified as CVE-2024-10924, exposes websites using the plugin to potential remote attacks, enabling threat actors to gain unauthorized administrative access.

Vulnerability Overview

The vulnerability affects versions 9.0.0 through 9.1.1.1 of the Simple Security plugin, including the Pro and Pro Multisite versions.

- Advertisement - Google News

Exploiting an authentication bypass flaw, attackers can remotely access any user account, including administrator accounts, if the “Two-Factor Authentication” feature is enabled.

Free Ultimate Continuous Security Monitoring Guide - Download Here (PDF)

The flaw stems from improper handling of user verification in the plugin’s two-factor REST API functions.

This security issue is particularly concerning due to its high CVSS score of 9.8, classifying it as “Critical.”

The vulnerability allows attackers to gain access to privileged accounts and take full control of affected websites.

A large-scale automated attack exploiting this flaw could potentially target millions of WordPress sites globally.

Vulnerability
Vulnerability

Upon identifying the issue on November 6, 2024, Wordfence Threat Intelligence began working closely with the plugin’s vendor to address the vulnerability.

The developer responded promptly, and a patched version of the plugin (9.1.2) was released on November 14, 2024.

The WordPress.org plugins team also initiated a forced update to ensure that most sites using the plugin are automatically updated to the secure version.

However, site owners are strongly advised to manually verify that their plugins are updated to version 9.1.2 or higher. Websites running older versions remain vulnerable to potential attacks.

With over 4 million websites still relying on this crucial plugin, site administrators are urged to check their WordPress installations and apply the update immediately.

Additionally, users of the Pro and Pro Multisite versions without auto-update enabled should manually install the latest patch to secure their sites.

Analyze Unlimited Phishing & Malware with ANY.RUN For Free - 14 Days Free Trial.



Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Windows Ancillary for WinSock 0-Day Vulnerability Actively Exploited to Gain Admin Access

Microsoft has confirmed active exploitation of a critical privilege escalation vulnerability in the Windows...

Earth Ammit Hackers Deploy New Tools to Target Military Drones

The threat actor group known as Earth Ammit, believed to be associated with Chinese-speaking...

New Microsoft Scripting Engine Vulnerability Exposes Systems to Remote Code Attacks

Critical zero-day vulnerability in Microsoft’s Scripting Engine (CVE-2025-30397) has been confirmed to enable remote...

Critical Microsoft Office Vulnerabilities Enable Malicious Code Execution

Microsoft has addressed three critical security flaws in its Office suite, including two vulnerabilities...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Windows Ancillary for WinSock 0-Day Vulnerability Actively Exploited to Gain Admin Access

Microsoft has confirmed active exploitation of a critical privilege escalation vulnerability in the Windows...

Earth Ammit Hackers Deploy New Tools to Target Military Drones

The threat actor group known as Earth Ammit, believed to be associated with Chinese-speaking...

New Microsoft Scripting Engine Vulnerability Exposes Systems to Remote Code Attacks

Critical zero-day vulnerability in Microsoft’s Scripting Engine (CVE-2025-30397) has been confirmed to enable remote...