HomeWordPress vulnerabilitiesReally Simple Security
Really Simple Security vulnerabilities
Really Simple Security has 6 known vulnerabilities in this database. The most recent published record is dated 18 Sep 2026.
- Known vulnerabilities
- 6
- Active installs
- 3m+
- Latest version
- 9.8.3
- Last updated
- 15 Sep 2026
- Most recent
- 18 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Denial of service CVE-2026-88798 | Medium 5.3 | Before 9.8.3 | Fixed in 9.8.3 | 18 Sep 2026 |
| Broken access control CVE-2026-82519 | Medium 4.3 | Before 9.8.2 | Fixed in 9.8.2 | 14 Sep 2026 |
| Authentication bypass CVE-2026-89080 | High 7.5 | Before 9.8.1 | Fixed in 9.8.1 | 13 Sep 2026 |
| Privilege escalation CVE-2026-81766 | Medium 6.6 | Before 9.8.0 | Fixed in 9.8.0 | 30 Aug 2026 |
| Authentication bypass CVE-2026-8293 | High 7.5 | Before 9.5.10.1 | Fixed in 9.5.10.1 | 2 Jun 2026 |
| Authentication bypass CVE-2024-10924 | Critical 9.8 | Before 9.1.2 | Fixed in 9.1.2 | 15 Nov 2024 |
Read the published descriptions
- CVE-2026-88798, 18 Sep 2026
- The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages. CVE record
- CVE-2026-82519, 14 Sep 2026
- Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a crafted POST request without the two-factor-authentication field to skip nonce verification and trigger delete_two_fa_meta(), which resets the grace period anchor timestamp on every login cycle, causing mandatory 2FA enforcement to be deferred indefinitely. CVE record
- CVE-2026-89080, 13 Sep 2026
- The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. CVE record
- CVE-2026-81766, 30 Aug 2026
- The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the network-shared Really Simple Security WordPress plugin before 9.8.0 directory, which WordPress otherwise reserves to the network administrator. Exploitation requires the network administrator to have enabled the Really Simple Security WordPress plugin before 9.8.0 administration menu for subsites, which is not the default. CVE record
- CVE-2026-8293, 2 Jun 2026
- The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge. CVE record
- CVE-2024-10924, 15 Nov 2024
- The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default). CVE record
What to do if you run Really Simple Security
If you run Really Simple Security, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Really Simple Security vulnerabilities
Free. We email you when a new vulnerability is published for Really Simple Security, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.