Executive brief
Really Simple SSL is a WordPress plugin used to enable HTTPS encryption and security on websites. A broken authentication vulnerability in versions 9.8.0 and earlier allows attackers to bypass the login system and gain unauthorized access to WordPress sites without valid credentials, potentially exposing customer data, website content, and administrative functions.
Technical details
The Really Simple SSL plugin contains a broken authentication vulnerability (classified as OWASP A7: Identification and Authentication Failures) that allows unauthenticated attackers to bypass the login mechanism. The vulnerability affects versions 9.8.0 and earlier; version 9.8.1 contains the fix. No special privileges or preconditions are required to exploit this vulnerability—an attacker needs only network access to the affected WordPress site. Successful exploitation enables an attacker to log in as arbitrary users, potentially gaining administrative access to the WordPress installation. The patch is available and users should immediately update to version 9.8.1 or later.
Affected products
- Really Simple SSL Really Simple SSL <=9.8.0
Timeline
- 2026-09-03: disclosed
- 2026-09-02: patched: Fix available in version 9.8.1