Medium · 4.5 WordPress CVE-2026-88798
Unauthenticated Denial-of-Service Flaw in Really Simple Security Plugin (CVE-2026-88798)
A vulnerability in the Really Simple Security WordPress plugin (before version 9.8.3) allows unauthenticated attackers to bloat a plugin option without limit, degrading how the site handles missing-page requests.
AI summary
A vulnerability has been identified in the Really Simple Security WordPress plugin (formerly Really Simple SSL), a widely used security plugin with millions of active installations. The issue, tracked as CVE-2026-88798, affects versions before 9.8.3 and allows an unauthenticated attacker to degrade site performance by abusing how the plugin stores certain client-supplied data.
What happened
The Really Simple Security plugin fails to validate a client-supplied address value before using it as a storage key in one of its own options. Because this value is not checked or limited, an unauthenticated attacker can repeatedly submit new values, causing the option to grow without bound. This has the effect of slowing down the site's handling of requests for missing pages (CWE-400: Uncontrolled Resource Consumption).
Technical cause
The root cause is a lack of input validation on a client-supplied value that is used directly as a key when writing to a plugin-managed option. Without bounds or sanitation checks, repeated submissions from an attacker can cause this option's data structure to expand indefinitely, consuming storage and processing resources over time.
Why it matters
The vulnerability can be triggered without authentication and without any user interaction, meaning any remote visitor can attempt to exploit it. While it does not expose data or allow code execution, it can gradually degrade site responsiveness, particularly for missing-page (404) handling, which may affect site availability and user experience over time.
Who is affected
Site owners running the Really Simple Security WordPress plugin, which according to available data has approximately 3 million active installations, are affected if running a version prior to 9.8.3.
Affected versions
All versions of Really Simple Security prior to 9.8.3 are affected.
Fixes and mitigation
The fact package indicates that a fix was referenced as fixed in version 9.8.3 in the plugin's vulnerability data; however, the record also explicitly marks fix_available as false. Due to this conflict in the available data, we cannot confirm with certainty that a patched release is currently published and available for download. Site owners should check their plugin update channel directly for the latest available version.
Recommended action
Administrators running Really Simple Security should check the WordPress plugin repository or their site's plugin dashboard for an update to version 9.8.3 or later. If no update is yet available, consider monitoring server logs for unusual request patterns targeting missing pages, and consult the plugin vendor's official channels for further guidance.
PatchBriefing score
4.5 / 10 · Medium
Official CVSS: 5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Why this score
This vulnerability has a CVSS base score of 5.3 (Medium), reflecting that it can be exploited remotely without authentication or user interaction, but only results in limited availability impact without affecting confidentiality or integrity. The PatchBriefing score of 4.5 incorporates additional factors: the unauthenticated and remote nature of the attack, the absence of required user interaction, the current lack of a confirmed available fix, and the plugin's high install base (approximately 3 million sites), which increases its overall relevance despite the lack of known exploitation or public exploit code.
Affected versions
- Really Simple Security < 9.8.3
- vulnerable
Reported fixes
The fact package indicates that a fix was referenced as fixed in version 9.8.3 in the plugin's vulnerability data; however, the record also explicitly marks fix_available as false. Due to this conflict in the available data, we cannot confirm with certainty that a patched release is currently published and available for download. Site owners should check their plugin update channel directly for the latest available version.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
WPVulnerability database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email