CVE-2026-48969: WordPress Really Simple SSL plugin <= 9.5.9 - Broken Access Control vulnerability
Published Jun 15, 2026
·Updated
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
Affected Software
1 affected component
wordpress/really-simple-ssl<=9.5.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Really Simple SSL Pluginto a version that resolves this vulnerability.Fixed in 9.5.10
Event History
Jun 15, 2026
CVE Published
via MITRE·12:58 PM
Data Sourced
via MITRE·12:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-48969?
The severity of CVE-2026-48969 is medium with a score of 6.5.
2
What type of vulnerability is described in CVE-2026-48969?
CVE-2026-48969 describes a Broken Access Control vulnerability in the Really Simple SSL plugin.
3
Which versions of the Really Simple SSL plugin are affected by CVE-2026-48969?
CVE-2026-48969 affects Really Simple SSL plugin versions 9.5.9 and earlier.
4
How do I fix CVE-2026-48969?
To fix CVE-2026-48969, update the Really Simple SSL plugin to the latest version.
5
What is the impact of CVE-2026-48969 on WordPress sites?
CVE-2026-48969 could allow unauthorized access to sensitive functionalities for subscribers.