CVE-2024-10245

CRITICAL

Relais 2FA plugin <1.0 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-10245. PoCs published by RandomRobbieBF.

AI-analyzed exploit summary The repository contains a functional proof-of-concept for an authentication bypass vulnerability in the Relais 2FA WordPress plugin. The exploit leverages incorrect authentication checks in the 'rl_do_ajax' function, allowing unauthenticated attackers to log in as any user with known email.

Description

The Relais 2FA plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0. This is due to incorrect authentication and capability checking in the 'rl_do_ajax' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

Exploits (1)

nomisec WORKING POC 1 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-10245

The repository contains a functional proof-of-concept for an authentication bypass vulnerability in the Relais 2FA WordPress plugin. The exploit leverages incorrect authentication checks in the 'rl_do_ajax' function, allowing unauthenticated attackers to log in as any user with known email.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Relais 2FA WordPress plugin <= 1.0
No auth needed
Prerequisites: known email of target user
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0116
EPSS Percentile 63.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-288
Status published
Products (1)
mobisoft974/Relais 2FA < 1.0
Published Nov 12, 2024
Tracked Since Feb 18, 2026