Known vulnerabilities in Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.
8Reported vulnerabilities
9.8Highest CVSS score
9.7.0Latest version
3,000,000+Active installs
What to do now
Update Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) to 9.8.0 or later.
8 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2024-10924 | Critical | 82.0% | 9.0.0 up to (but not including) 9.1.2 | 9.1.2 |
November 15, 2024 |
| CVE-2026-81766 | High | 0.3% | Before 9.8.0 | 9.8.0 |
August 31, 2026 |
| CVE-2024-31229 | Medium | 0.3% | 7.2.3 and earlier | 8.0.0 |
April 16, 2024 |
| CVE-2026-8293 | Medium | 0.2% | 9.5.10.0 and earlier | 9.5.10.1 |
June 12, 2026 |
| CVE-2026-48970 | Medium | 0.4% | 9.5.10 and earlier | 9.5.10.1 |
June 3, 2026 |
| CVE-2026-48969 | Medium | 0.3% | 9.5.9 and earlier | 9.5.10 |
June 3, 2026 |
| CVE-2026-32461 | Medium | 0.2% | 9.5.7 and earlier | 9.5.8 |
March 15, 2026 |
| CVE-2025-24623 | Medium | 0.2% | 9.1.4 and earlier | 9.2.0 |
January 24, 2025 |