Junglewise Threat Intelligence

CVE-2026-84777: Really Simple SSL broken authentication in login

CVE-2026-84777 · Severity: high · CVSS 7.4 · Published 2026-09-03

Technologies: Really Simple SSL.

Executive brief

Really Simple SSL is a WordPress plugin used to enable HTTPS encryption and security on websites. A broken authentication vulnerability in versions 9.8.0 and earlier allows attackers to bypass the login system and gain unauthorized access to WordPress sites without valid credentials, potentially exposing customer data, website content, and administrative functions.

Technical details

The Really Simple SSL plugin contains a broken authentication vulnerability (classified as OWASP A7: Identification and Authentication Failures) that allows unauthenticated attackers to bypass the login mechanism. The vulnerability affects versions 9.8.0 and earlier; version 9.8.1 contains the fix. No special privileges or preconditions are required to exploit this vulnerability—an attacker needs only network access to the affected WordPress site. Successful exploitation enables an attacker to log in as arbitrary users, potentially gaining administrative access to the WordPress installation. The patch is available and users should immediately update to version 9.8.1 or later.

Affected products

  • Really Simple SSL Really Simple SSL <=9.8.0

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: Fix available in version 9.8.1

References