To access material, start machines and answer questions login.
Set up your virtual environment
WordPress is one of the most popular open-source Content Management Systems () and it is widely used to build websites ranging from blogs to e-commerce platforms. In November 2024, a critical vulnerability was discovered in the Really Simple Security plugin (opens in new tab), a widely adopted security plugin used by millions of websites. The vulnerability allowed attackers to bypass authentication and gain unauthorised access to user accounts, including those with administrative privileges. Since WordPress is a , gaining administrative access sometimes allows you even to perform privilege escalation and get complete control of the server/network. Discovered by István Márton from Wordfence (opens in new tab), this flaw was assigned a critical severity rating and -ID 2024-10924.
Learning Objective
- Exploit a WordPress authentication through 2024-10924
- How the exploit works
- Protection and mitigation measures
Room Pre-requisites
Understanding the following topics is recommended before starting the room:
Connecting to the Machine
You can start the lab machine by clicking the Start Lab Machine button, which will start the machine in a split-screen view. If the VM is not visible, use the blue Show Split View button at the top of the page. Please wait 1-2 minutes after the system boots completely to let the auto scripts run successfully.
Ready to learn Cyber Security?
The Bypass Really Simple Security room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in

