CVE-2026-84775: WordPress Really Simple SSL plugin <= 9.8.0 - Denial of Service Attack vulnerability
Published Sep 2, 2026
·Updated
Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
Affected Software
1 affected component
wordpress/really-simple-ssl<=9.8.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Really Simple SSLto a version that resolves this vulnerability.Fixed in 9.8.1
Event History
Sep 2, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated and remotely reachable, so an attacker does not need a WordPress account or user interaction to attempt exploitation.
2
What is the likely impact of a successful attack?
The documented impact is denial of service, affecting availability. The supplied severity vector indicates no stated confidentiality or integrity impact.
3
Which installations are affected?
Really Simple SSL versions 9.8.0 and earlier are identified as affected. The provided data does not state whether any particular plugin configuration is required.