Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.1 WordPress CVE-2026-89080 CVE-2026-82519

Two Two-Factor Authentication Bypass Flaws Found in Really Simple Security WordPress Plugin

Really Simple Security, a WordPress plugin used on roughly 3 million sites, is affected by two separate vulnerabilities (CVE-2026-89080 and CVE-2026-82519) that allow attackers to bypass two-factor authentication enforcement. No fixed version has been confirmed in the available data.

Synthesized by AI from 4 sources · updated 1 hour ago

AI summary

Two distinct vulnerabilities have been disclosed in Really Simple Security, a WordPress security plugin (formerly Really Simple SSL) with a large install base. Both issues undermine the plugin's two-factor authentication (2FA) protections, though through different mechanisms and with different attacker prerequisites. This briefing covers CVE-2026-89080 and CVE-2026-82519 together because they affect the same product area and were disclosed within days of each other.

What happened

Two vulnerabilities were disclosed affecting Really Simple Security, a WordPress plugin. CVE-2026-89080 allows an unauthenticated attacker who already knows an account's password to reset that account's completed email two-factor enrolment, bypassing the second authentication factor and obtaining that user's session, potentially up to administrator level. CVE-2026-82519 is a separate missing-authorization-check issue that allows an authenticated low-privileged attacker to bypass enforced two-factor authentication indefinitely by submitting a crafted request to the profile-page update handler, which skips nonce verification and triggers a function that resets the 2FA grace-period timer on every login cycle.

Technical cause

CVE-2026-89080 is classified under CWE-287 (Improper Authentication): the plugin does not adequately protect the process of resetting a completed email-based 2FA enrolment, allowing it to be triggered without authentication by someone who already holds valid account credentials. CVE-2026-82519 is classified under CWE-862 (Missing Authorization): the profile-page update handler contains an unguarded code path. Submitting a POST request without the two-factor-authentication field skips nonce verification and calls a function described as delete_two_fa_meta(), which resets the grace-period anchor timestamp on each login, deferring mandatory 2FA enforcement indefinitely.

Why it matters

Two-factor authentication is a key control against account takeover when passwords are compromised through phishing, credential stuffing, or reuse. Both vulnerabilities allow that control to be bypassed. CVE-2026-89080 is particularly notable because it requires no further authentication beyond already knowing the account password, and it can affect accounts up to administrator level, which on WordPress typically means full site control. CVE-2026-82519 requires existing low-privileged account access but allows an attacker to indefinitely defer mandatory 2FA enforcement for themselves, undermining site-wide 2FA policy.

Who is affected

Any WordPress site running the affected versions of the Really Simple Security plugin with two-factor authentication enabled is potentially affected. The plugin has a large install base (on the order of millions of sites), though the exact number of sites running vulnerable versions is not specified in the available data.

Affected versions

CVE-2026-89080 affects Really Simple Security versions before 9.8.1. CVE-2026-82519 affects versions before 9.8.2. The fact package does not specify the starting version of the affected range for either issue, nor does it confirm a fixed_versions list beyond the version strings referenced in the advisory titles.

Fixes and mitigation

The available data marks fix_available as false for both CVE-2026-89080 and CVE-2026-82519, meaning no confirmed fixed release is documented in the fact package, despite the advisory titles referencing versions 9.8.1 and 9.8.2 as the upper bound of the affected range. Site owners should check the official plugin changelog and WordPress.org plugin page directly to confirm current patch status before assuming an update has resolved these issues.

Recommended action

Site administrators running Really Simple Security should verify their installed version against the plugin's official update channel and apply any available update promptly. Given the uncertainty around fix availability in this data, administrators should independently confirm patch status via the WordPress.org plugin repository before relying on version numbers alone. As a general precaution, review user accounts with 2FA enrolled for unexpected resets or changes, and consider rotating passwords for administrator-level accounts.

PatchBriefing score

5.1 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Why this score

CVE-2026-89080 has a CVSS base score of 7.5 and a PatchWire score of 5.1. The CVSS vector indicates network attack vector, high attack complexity, low privileges required (a known password), no user interaction, and high impact to confidentiality, integrity, and availability due to the potential to reach administrator-level sessions. The PatchWire score factors in the CVSS base contribution (4.13), no user interaction (+0.2), no fix currently available (+0.4), and the plugin's large install base (+0.4), with no known exploitation or public exploit code increasing the score. CVE-2026-82519 has a lower CVSS base score of 4.3 and PatchWire score of 3.4, reflecting that it requires low-privileged authentication, has no confidentiality impact, low integrity impact, and no availability impact — it weakens a security control rather than directly compromising data or systems. Neither vulnerability is flagged as known exploited or has public exploit code reported in this data.

Affected versions

Really Simple Security < 9.8.1
vulnerable
Really Simple Security < 9.8.2
vulnerable

Reported fixes

The available data marks fix_available as false for both CVE-2026-89080 and CVE-2026-82519, meaning no confirmed fixed release is documented in the fact package, despite the advisory titles referencing versions 9.8.1 and 9.8.2 as the upper bound of the affected range. Site owners should check the official plugin changelog and WordPress.org plugin page directly to confirm current patch status before assuming an update has resolved these issues.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
  • NVD (NIST) database
  • WPVulnerability database
  • NVD (NIST) database
Unified report
Two Two-Factor Authentication Bypass Flaws Found in Really Simple Security WordPress Plugin
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email