Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesReally Simple Security

Really Simple Security vulnerabilities

Really Simple Security has 6 known vulnerabilities in this database. The most recent published record is dated 18 Sep 2026.

Known vulnerabilities
6
Active installs
3m+
Latest version
9.8.3
Last updated
15 Sep 2026
Most recent
18 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Denial of service
CVE-2026-88798
Medium 5.3Before 9.8.3Fixed in 9.8.318 Sep 2026
Broken access control
CVE-2026-82519
Medium 4.3Before 9.8.2Fixed in 9.8.214 Sep 2026
Authentication bypass
CVE-2026-89080
High 7.5Before 9.8.1Fixed in 9.8.113 Sep 2026
Privilege escalation
CVE-2026-81766
Medium 6.6Before 9.8.0Fixed in 9.8.030 Aug 2026
Authentication bypass
CVE-2026-8293
High 7.5Before 9.5.10.1Fixed in 9.5.10.12 Jun 2026
Authentication bypass
CVE-2024-10924
Critical 9.8Before 9.1.2Fixed in 9.1.215 Nov 2024
Read the published descriptions
CVE-2026-88798, 18 Sep 2026
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages. CVE record
CVE-2026-82519, 14 Sep 2026
Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a crafted POST request without the two-factor-authentication field to skip nonce verification and trigger delete_two_fa_meta(), which resets the grace period anchor timestamp on every login cycle, causing mandatory 2FA enforcement to be deferred indefinitely. CVE record
CVE-2026-89080, 13 Sep 2026
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. CVE record
CVE-2026-81766, 30 Aug 2026
The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the network-shared Really Simple Security WordPress plugin before 9.8.0 directory, which WordPress otherwise reserves to the network administrator. Exploitation requires the network administrator to have enabled the Really Simple Security WordPress plugin before 9.8.0 administration menu for subsites, which is not the default. CVE record
CVE-2026-8293, 2 Jun 2026
The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge. CVE record
CVE-2024-10924, 15 Nov 2024
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default). CVE record

What to do if you run Really Simple Security

If you run Really Simple Security, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Really Simple Security vulnerabilities

Free. We email you when a new vulnerability is published for Really Simple Security, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support