# CVE-2026-89080

## Summary

- **CVE ID:** CVE-2026-89080
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 13, 2026
- **Last Modified:** Sep 13, 2026

## Description

The Really Simple Security  WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.

## Affected Products

- Unknown — Really Simple Security (9.5.10.1)

## References

- [CNA](https://wpscan.com/vulnerability/49546064-5663-40f8-be7c-4f3faa31fa9a/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 10.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._