CVE-2026-84777: WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.
Affected Software
1 affected component
Really Simple SSL<=9.8.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Really Simple SSL pluginto a version that resolves this vulnerability.Fixed in 9.8.1
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Really Simple SSL versions 9.8.0 and earlier are affected.
2
Does exploitation require an authenticated WordPress account or user interaction?
No. The vulnerability is described as unauthenticated, and the vector indicates no privileges or user interaction are required.
3
What security impact could successful exploitation have?
Successful exploitation could affect confidentiality and integrity at a high level. Availability impact is listed as none.
4
How difficult is exploitation expected to be?
The attack vector is network-based, but the listed attack complexity is high.