Junglewise Threat Intelligence

CVE-2026-48969: Really Simple SSL broken access control in WordPress plugin

CVE-2026-48969 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: Really Simple Plugins Really Simple SSL. Vendors: Really Simple Plugins.

Executive brief

Really Simple SSL is a popular WordPress plugin used to manage security settings and SSL certificates. A security flaw allows users with basic 'Subscriber' accounts to bypass security checks and perform actions they should not be authorized to do. This could allow an attacker with a low-level account to modify site settings or interfere with the website's security configuration.

Technical details

The Really Simple SSL plugin for WordPress (versions 9.5.9 and below) contains a broken access control vulnerability classified as CWE-862 (Missing Authorization). The flaw exists because the plugin fails to properly validate user permissions or nonces on certain functions. An attacker authenticated with low-level 'Subscriber' privileges can exploit this to execute higher-privileged actions, potentially modifying plugin settings or site configurations. The vulnerability is reachable over the network and requires basic authentication. A patch is available in version 9.5.10.

Affected products

  • Really Simple SSL Really Simple SSL <= 9.5.9

Timeline

  • 2026-03-29: other: Vulnerability reported by researcher
  • 2026-06-03: patched: Version 9.5.10 released
  • 2026-06-15: disclosed: NVD publication date

References

Related threats