SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-89080

HIGH · CVSS 7.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The Really Simple Security plugin for WordPress versions prior to 9.8.1 is vulnerable to unauthorized account access due to insufficient protection against unauthenticated requests, allowing attackers with knowledge of the account password to reset two-factor authentication settings. This weakness can lead to session hijacking, potentially granting attackers administrative access. WordPress site administrators and users of the affected plugin should prioritize updating to the latest version to mitigate this high-severity risk.

CVE
CVE-2026-89080
Severity
HIGH
CVSS
7.5
EPSS
N/A
WordPress

Original NVD Description

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.