plugin

Really Simple Ssl Vulnerabilities

8 known security issues reported for the Really Simple Ssl WordPress plugin. Most recent disclosed Jun 12, 2026.

1 critical 7 medium

Running Really Simple Ssl on your site? Check whether your installed version is affected.

Scan your site free

Really Simple Security <= 9.5.10.0 - Two Factor Authentication Bypass

medium

The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulnerable to Two Factor Authentication Bypass in all versions up to, and including, 9.5.10.0. This makes it possible for unauthenticated attackers to bypass the second factor of authentication when the firs...

CVSS:
5.3
Affected:
up to 9.5.10.0
Fixed in:
9.5.10.1
Disclosed:
Jun 12, 2026

CVE-2026-8293 on NVD →

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.10 - Missing Authorization

medium

The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 9.5.10. This makes it possible for unauthenticated attackers to perform an unauthorized...

CVSS:
5.3
Affected:
up to 9.5.10
Fixed in:
9.5.10.1
Disclosed:
Jun 3, 2026

CVE-2026-48970 on NVD →

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.9 - Missing Authorization

medium

The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 9.5.9. This makes it possible for authenticated attackers, with subscriber-level access and...

CVSS:
4.3
Affected:
up to 9.5.9
Fixed in:
9.5.10
Disclosed:
Jun 3, 2026

CVE-2026-48969 on NVD →

Really Simple SSL - Broken Access Control vulnerability

medium

Broken Access Control vulnerability

CVSS:
4.3
Affected:
up to 9.5.7
Fixed in:
9.5.8
Disclosed:
Mar 15, 2026

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.7 - Missing Authorization

medium

The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 9.5.7. This makes it possible for authenticated attackers, with Subscriber-level access...

CVSS:
4.3
Affected:
up to 9.5.7
Fixed in:
9.5.8
Disclosed:
Mar 15, 2026

CVE-2026-32461 on NVD →

Really Simple SSL <= 9.1.4 - Cross-Site Request Forgery

medium

The Really Simple SSL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.1.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...

CVSS:
4.3
Affected:
up to 9.1.4
Fixed in:
9.2.0
Disclosed:
Jan 24, 2025

CVE-2025-24623 on NVD →

Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass

critical

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthentica...

CVSS:
9.8
Affected:
9.0.0 – 9.1.1.1
Fixed in:
9.1.2
Disclosed:
Nov 14, 2024

CVE-2024-10924 on NVD →

Really Simple SSL <= 7.2.3 - Authenticated (Admin+) Server-Side Request Forgery

medium

The Really Simple SSL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.2.3. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can b...

CVSS:
5.5
Affected:
up to 7.2.3
Fixed in:
8.0.0
Disclosed:
Apr 16, 2024

CVE-2024-31229 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database