Really Simple Security <= 9.5.10.0 - Two Factor Authentication Bypass
medium
The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulnerable to Two Factor Authentication Bypass in all versions up to, and including, 9.5.10.0. This makes it possible for unauthenticated attackers to bypass the second factor of authentication when the firs...
- CVSS:
- 5.3
- Affected:
- up to 9.5.10.0
- Fixed in:
- 9.5.10.1
- Disclosed:
- Jun 12, 2026
CVE-2026-8293 on NVD →
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.10 - Missing Authorization
medium
The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 9.5.10. This makes it possible for unauthenticated attackers to perform an unauthorized...
- CVSS:
- 5.3
- Affected:
- up to 9.5.10
- Fixed in:
- 9.5.10.1
- Disclosed:
- Jun 3, 2026
CVE-2026-48970 on NVD →
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.9 - Missing Authorization
medium
The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 9.5.9. This makes it possible for authenticated attackers, with subscriber-level access and...
- CVSS:
- 4.3
- Affected:
- up to 9.5.9
- Fixed in:
- 9.5.10
- Disclosed:
- Jun 3, 2026
CVE-2026-48969 on NVD →
Really Simple SSL - Broken Access Control vulnerability
medium
Broken Access Control vulnerability
- CVSS:
- 4.3
- Affected:
- up to 9.5.7
- Fixed in:
- 9.5.8
- Disclosed:
- Mar 15, 2026
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.7 - Missing Authorization
medium
The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 9.5.7. This makes it possible for authenticated attackers, with Subscriber-level access...
- CVSS:
- 4.3
- Affected:
- up to 9.5.7
- Fixed in:
- 9.5.8
- Disclosed:
- Mar 15, 2026
CVE-2026-32461 on NVD →
Really Simple SSL <= 9.1.4 - Cross-Site Request Forgery
medium
The Really Simple SSL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.1.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 9.1.4
- Fixed in:
- 9.2.0
- Disclosed:
- Jan 24, 2025
CVE-2025-24623 on NVD →
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
critical
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthentica...
- CVSS:
- 9.8
- Affected:
- 9.0.0 – 9.1.1.1
- Fixed in:
- 9.1.2
- Disclosed:
- Nov 14, 2024
CVE-2024-10924 on NVD →
Really Simple SSL <= 7.2.3 - Authenticated (Admin+) Server-Side Request Forgery
medium
The Really Simple SSL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.2.3. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can b...
- CVSS:
- 5.5
- Affected:
- up to 7.2.3
- Fixed in:
- 8.0.0
- Disclosed:
- Apr 16, 2024
CVE-2024-31229 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database