ZeroHour

CVE-2026-84777

mass

Unauthenticated Broken Authentication in Really Simple SSL WordPress Plugin

CVSS 3.1
7.4 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-84777 is an unauthenticated broken-authentication vulnerability (CWE-288) in the Really Simple SSL plugin for WordPress, affecting all versions up to and including 9.8.0. An unauthenticated remote attacker can trigger the flaw over the network without credentials or user interaction, although the high attack-complexity score component indicates that specific conditions must be met for exploitation to succeed. Successful exploitation produces high confidentiality and integrity impact with no availability impact, consistent with an attacker bypassing authentication to gain unauthorized access to a privileged user's account or session on the affected site. Any WordPress site running Really Simple SSL 9.8.0 or earlier is affected, and the plugin's multi-million active-install base means exposure is broad. Exploitation status is currently low-risk: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Update Really Simple SSL to a version later than 9.8.0 as soon as a patched release is available. Until then, harden authentication at the site perimeter (e.g., allowlist or rate-limit access to wp-login.php, enforce 2FA via another mechanism) and review authentication logs for unexpected successful logins. With no public PoC or known in-the-wild exploitation, immediate risk is low, but the plugin's large install base makes prompt patching advisable.

Affected
Really Simple SSL (WordPress plugin)<= 9.8.0
Estimated exposure
mass≈4–5 million WordPress sites (plugin has multi-million active installs on WordPress.org) — Really Simple SSL is one of the most widely installed WordPress security plugins, with several million active installations publicly reported on WordPress.org, and all sites running version 9.8.0 or earlier are in scope.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.

Ecosystems
WordPress
Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.