Executive brief
Really Simple SSL is a popular WordPress plugin used to manage security settings and SSL certificates. A security flaw in this plugin could allow an attacker to bypass authentication and gain administrative access to a website. While the attack requires the attacker to have already obtained a user's password, this vulnerability allows them to bypass further security checks to take full control of the site.
Technical details
The Really Simple SSL plugin for WordPress (versions up to 9.5.10) contains a broken authentication vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The flaw allows an unauthenticated attacker to bypass standard authentication mechanisms, potentially gaining administrative privileges. According to the advisory, a significant precondition is that the attacker must already possess the victim's password, which increases the attack complexity (AC:H). The vulnerability is addressed in version 9.5.10.1. Due to the nature of the flaw, traditional virtual patching may not be effective, making a direct plugin update the primary remediation.
Affected products
- Really Simple SSL Really Simple SSL <= 9.5.10
Timeline
- 2026-04-17: disclosed: Reported by Septio Noerdiansyah
- 2026-06-03: advisory: Patchstack published advisory
- 2026-06-15: advisory: NVD published CVE-2026-48970
- 2026-06-03: patched: Fixed in version 9.5.10.1