WP Vulnerability WatchVulnerability data as of September 15, 2026

Vulnerability alerts / September 14, 2026

Vulnerability in Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) — CVE-2026-82519

LowSeverity
CVSS 2.3
Estimated exploit probability
EPSS
3,000,000+ sitesInstalls
9.8.2Fixed in

What to do now

Update Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) to 9.8.2 or later.

Affected versions

  • Everything before 9.8.2

Affected: Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) (plugin, really-simple-ssl)

Check: The plugin on wordpress.org / Our record for Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)

What the vulnerability is

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a crafted POST request without the two-factor-authentication field to skip nonce verification and trigger delete_two_fa_meta(), which resets the grace period anchor timestamp on every login cycle, causing mandatory 2FA enforcement to be deferred indefinitely.

This description is reproduced verbatim from the public vulnerability record.

Sources

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts