CVE-2026-32461: WordPress Really Simple SSL plugin <= 9.5.7 - Broken Access Control vulnerability
Published Mar 13, 2026
·Updated
Missing Authorization vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple SSL: from n/a through <= 9.5.7.
Affected Software
1 affected component
wordpress/really-simple-ssl<=9.5.7
Event History
Mar 13, 2026
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-32461?
CVE-2026-32461 is classified as a Broken Access Control vulnerability with a risk of unauthorized access.
2
How do I fix CVE-2026-32461?
To fix CVE-2026-32461, upgrade the Really Simple SSL plugin to version 9.5.8 or later.
3
What systems are affected by CVE-2026-32461?
CVE-2026-32461 affects the Really Simple SSL plugin in WordPress versions up to and including 9.5.7.
4
What type of vulnerability is CVE-2026-32461?
CVE-2026-32461 is a Missing Authorization vulnerability due to incorrectly configured access control levels.
5
Can CVE-2026-32461 be exploited without authentication?
Yes, CVE-2026-32461 can be exploited without proper authentication due to broken access controls.