Vulnerability in Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) — CVE-2026-81766
HighSeverity
0.3%Estimated exploit probability
3,000,000+ sitesInstalls
9.8.0Fixed in
What to do now
Update Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) to 9.8.0 or later.
Affected versions
- Everything before 9.8.0
Affected: Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) (plugin, really-simple-ssl)
What the vulnerability is
The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 9.8.0. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for authenticated attackers, with custom role-level access and above, to execute arbitrary code on the server.