Junglewise Threat Intelligence

CVE-2026-84775: Really Simple SSL denial of service attack

CVE-2026-84775 · Severity: medium · CVSS 5.3 · Published 2026-09-02

Executive brief

Really Simple SSL is a popular WordPress plugin that manages SSL certificate installation and HTTPS redirection. An unauthenticated attacker can send specially crafted requests to overwhelm the plugin's functionality, causing the website to become slow or go offline without requiring any credentials or user interaction.

Technical details

Really Simple SSL plugin versions 9.8.0 and earlier contain a denial of service vulnerability that can be triggered without authentication. An attacker can send unauthenticated requests that cause resource exhaustion or processing loops, degrading site performance or making it unavailable. The vulnerability is classified as an insecure design flaw (OWASP A4) in the plugin's request handling logic. The attack requires only network access and no user interaction. Patched in version 9.8.1; administrators should update immediately.

Affected products

  • Wordfence Really Simple SSL <=9.8.0

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Patched in version 9.8.1

References