Executive brief
Really Simple SSL is a popular WordPress plugin used to manage security settings and SSL certificates. A security flaw allows users with basic 'Subscriber' accounts to bypass security checks and perform actions they should not be authorized to do. This could allow an attacker with a low-level account to modify site settings or interfere with the website's security configuration.
Technical details
The Really Simple SSL plugin for WordPress (versions 9.5.9 and below) contains a broken access control vulnerability classified as CWE-862 (Missing Authorization). The flaw exists because the plugin fails to properly validate user permissions or nonces on certain functions. An attacker authenticated with low-level 'Subscriber' privileges can exploit this to execute higher-privileged actions, potentially modifying plugin settings or site configurations. The vulnerability is reachable over the network and requires basic authentication. A patch is available in version 9.5.10.
Affected products
- Really Simple SSL Really Simple SSL <= 9.5.9
Timeline
- 2026-03-29: other: Vulnerability reported by researcher
- 2026-06-03: patched: Version 9.5.10 released
- 2026-06-15: disclosed: NVD publication date