Critical vulnerability in the popular WordPress safety plug: deep analysis

Article image Critical vulnerability in the popular WordPress safety plug: deep analysis
Article image Critical vulnerability in the popular WordPress safety plug: deep analysis
Publication date:06.10.2025
Blog category: Web Security

Really Simple Security is a WordPress plugin designed to enhance WordPress websites against operation, inclusion of two -factor authentication, vulnerable vulnerabilities, and SSL certificate generation. One of the reasons he advertises as easy is that it is a modular software that allows users to choose which safety improvements are to be switched on so that the processes for disabled functionality do not download or slow down the website.

"Really Simple Security (Free, Pro, and Pro Multisite) WordPress plugins are vulnerable to bypass authentication in versions from 9.0.0 to 9.1.1.1.1. This is due to improper processing Unaffected attackers to enter any existing user on the site, for example, as an administrator, when the "two-factor authentication" setting is included (default).

🚀 If you use the Really Simple Security plugin, it is recommended that you immediately update it to Version 9.1.2 or above. Update contains correction for this vulnerability. Despite the fact that Wordfence has already blocked several attacks aimed at this vulnerability, it is important to stay up to date with security updates to protect your website from potential threats.

  • 📌 You can use vulnerability to access any registered website, including the administrator, simply knowing the username.
  • 📌 This is known as vulnerability to non -authenticated access, one of the most serious types of shortcomings, since it is generally easier to operate than an "authenticated" shortcomings that requires the attacker to first get a username and password of a registered user.
  • 📌 Wordfence has already blocked 310 attacks aimed at this vulnerability for the last 24 hours.
FAQ

Which WordPress plugin was vulnerable?

Really Simple Security.

What if I use this plugin?

Update the plugin to version 9.1.2 or above.

Why is this vulnerability serious?

It allows the attackers to bypass authentication and access to any user account, including the administrator.

🧩 Summary: A recent detection of critical vulnerability in the popular WordPress Plugin Really Simple Security emphasizes the importance of constant updating and monitoring of the website safety. Vulnerability allows the attackers to access any user account, including the administrator simply by knowing the username. The WordFense team has already blocked many attacks aimed at this vulnerability, although it is important to stay up to date with security updates.
🧠 Own considerations: This case is a reminder to all developers and website owners about the importance of constant updating and audit of safety of their websites. Even safety plugins may contain vulnerabilities that emphasize the need to be aware of the latest security updates and check your website regularly for vulnerability.