Unauthenticated Broken Authentication in Really Simple SSL Plugin by Really Simple SSL
CVE-2026-84777
7.4HIGH
What is CVE-2026-84777?
The Really Simple SSL plugin for WordPress has a vulnerability that allows unauthenticated users to bypass authentication mechanisms. This flaw exists in versions up to 9.8.0, potentially enabling attackers to impersonate legitimate users or gain unauthorized access to sensitive areas of a website.
Affected Version(s)
Really Simple SSL <= 9.8.0
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program