VDB
BDU%3A2024-09749
BDU%3A2024-09749
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Уязвимость плагинов Really Simple Security Free, Really Simple Security Pro и Really Simple Security Pro Multisite системы управления содержимым сайта WordPress, позволяющая нарушителю повысить свои привилегии
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Really Simple Plugins | Really Simple Security Pro | 9.0.0 |
| Really Simple Plugins | Really Simple Security Pro multisite | 9.0.0 |
| rogierlankhorst | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) | 9.0.0 |
| WordPress Foundation | really-simple-ssl, really-simple-ssl-pro, really-simple-ssl-pro-multisite | |
| really-simple-plugins | really_simple_security | 9.0.0 |
Timeline
- Nov 15, 2024 CVE Published
- Nov 15, 2024 PoC Published
- Nov 15, 2024 PoC Published
- Nov 15, 2024 PoC Published
- Nov 17, 2024 PoC Published
- Nov 18, 2024 CVE Updated
- Nov 18, 2024 PoC Published
- Nov 18, 2024 PoC Published
- Nov 18, 2024 PoC Published
- Nov 18, 2024 PoC Published
- Nov 18, 2024 PoC Published
- Nov 18, 2024 PoC Published
References
- https://www.tenable.com/cve/CVE-2024-10924 url
- https://www.wordfence.com/threat-intel/vulnerabilities/id/7d5d05ad-1a7a-43d2-bbbf-597e975446be?source=cve url
- https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L67 url
- https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L278 url
- https://plugins.trac.wordpress.org/changeset/3188431/really-simple-ssl url
- https://www.wordfence.com/blog/2024/11/really-simple-security-vulnerability/ url
- https://github.com/JoshuaProvoste/0-click-RCE-Exploit-for-CVE-2024-10924 url
- https://securityonline.info/cve-2024-10924-cvss-9-8-authentication-bypass-in-really-simple-security-plugin-affects-4-million-sites/#google_vignette url
- https://vuldb.com/ru/?id.284578 url
- https://patchstack.com/articles/critical-account-takeover-patched-in-really-simple-security-plugin/ url
- https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L277 url