Junglewise Threat Intelligence

CVE-2026-48970: Really Simple SSL broken authentication in WordPress plugin

CVE-2026-48970 · Severity: high · CVSS 8.1 · Published 2026-06-15

Technologies: Really Simple SSL. Vendors: Really Simple Plugins.

Executive brief

Really Simple SSL is a popular WordPress plugin used to manage security settings and SSL certificates. A security flaw in this plugin could allow an attacker to bypass authentication and gain administrative access to a website. While the attack requires the attacker to have already obtained a user's password, this vulnerability allows them to bypass further security checks to take full control of the site.

Technical details

The Really Simple SSL plugin for WordPress (versions up to 9.5.10) contains a broken authentication vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The flaw allows an unauthenticated attacker to bypass standard authentication mechanisms, potentially gaining administrative privileges. According to the advisory, a significant precondition is that the attacker must already possess the victim's password, which increases the attack complexity (AC:H). The vulnerability is addressed in version 9.5.10.1. Due to the nature of the flaw, traditional virtual patching may not be effective, making a direct plugin update the primary remediation.

Affected products

  • Really Simple SSL Really Simple SSL <= 9.5.10

Timeline

  • 2026-04-17: disclosed: Reported by Septio Noerdiansyah
  • 2026-06-03: advisory: Patchstack published advisory
  • 2026-06-15: advisory: NVD published CVE-2026-48970
  • 2026-06-03: patched: Fixed in version 9.5.10.1

References

Related threats