A critical vulnerability in the Really Simple Security plugin affects over 4 million WordPress sites.The vulnerability allows attackers to gain full admin access to affected sites.The flaw is an authentication bypass vulnerability in the plugin's two-factor authentication feature.The vulnerability has been patched in version 9.1.2 of the plugin.