CVE-2026-8293: Unknown Really Simple Security

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge.

Affected products

  • Unknown Really Simple Security: before 9.5.10.1 (fixed in 9.5.10.1)

Published 2026-06-02. Last modified 2026-07-22.