CVE-2026-84777
massUnauthenticated Broken Authentication in Really Simple SSL WordPress Plugin
CVE-2026-84777 is an unauthenticated broken-authentication vulnerability (CWE-288) in the Really Simple SSL plugin for WordPress, affecting all versions up to and including 9.8.0. An unauthenticated remote attacker can trigger the flaw over the network without credentials or user interaction, although the high attack-complexity score component indicates that specific conditions must be met for exploitation to succeed. Successful exploitation produces high confidentiality and integrity impact with no availability impact, consistent with an attacker bypassing authentication to gain unauthorized access to a privileged user's account or session on the affected site. Any WordPress site running Really Simple SSL 9.8.0 or earlier is affected, and the plugin's multi-million active-install base means exposure is broad. Exploitation status is currently low-risk: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Update Really Simple SSL to a version later than 9.8.0 as soon as a patched release is available. Until then, harden authentication at the site perimeter (e.g., allowlist or rate-limit access to wp-login.php, enforce 2FA via another mechanism) and review authentication logs for unexpected successful logins. With no public PoC or known in-the-wild exploitation, immediate risk is low, but the plugin's large install base makes prompt patching advisable.
| Really Simple SSL (WordPress plugin) | <= 9.8.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-288
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.