WP Vulnerability WatchVulnerability data as of September 7, 2026

Vulnerability alerts / August 31, 2026

Vulnerability in Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) — CVE-2026-81766

HighSeverity
CVSS 8.8
0.3%Estimated exploit probability
EPSS
3,000,000+ sitesInstalls
9.8.0Fixed in

What to do now

Update Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) to 9.8.0 or later.

Affected versions

  • Everything before 9.8.0

Affected: Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) (plugin, really-simple-ssl)

Check: The plugin on wordpress.org / Our record for Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)

What the vulnerability is

The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 9.8.0. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for authenticated attackers, with custom role-level access and above, to execute arbitrary code on the server.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/b52427e6-dfe2-42be-af2a-6ee5a1e22bf5
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts