Description
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Cross Site Request Forgery.This issue affects Really Simple SSL: from n/a through <= 9.1.4.
Published: 2025-01-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits an attacker to inject forged HTTP requests that the Really Simple SSL plugin blindly accepts and acts upon. Because the plugin lacks adequate anti‑CSRF safeguards, authenticated users who visit a malicious page can be tricked into submitting requests that trigger changes to the site’s configuration or content. This can expose the site to unauthorized administrative actions. The primary impact is the potential to alter site settings or data, but it does not directly compromise confidential data or allow arbitrary code execution.

Affected Systems

Really Simple SSL plugin by Really Simple Plugins, versions up to and including 9.1.4 are affected. The vulnerability applies to any installation of the plugin within WordPress that has not been upgraded beyond 9.1.4.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires a victim who is logged into the WordPress administrator account to be induced to visit a crafted URL; the request is then forwarded to the site and processed by the plugin, allowing the attacker to execute privileged operations. No public exploit has been documented, and the exploitation path relies on user interaction.

Generated by OpenCVE AI on May 1, 2026 at 18:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Really Simple SSL to version 9.1.5 or later, ensuring the latest fixed code is in place.
  • If an upgrade is not immediately possible, disable the plugin or remove the offending functionality from the site until a patch can be applied.
  • Enable two‑factor authentication for all WordPress administrative accounts to reduce the risk that a forged request can succeed against a compromised session.

Generated by OpenCVE AI on May 1, 2026 at 18:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3825 Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Security Really Simple SSL allows Cross Site Request Forgery. This issue affects Really Simple SSL: from n/a through 9.1.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Security Really Simple SSL allows Cross Site Request Forgery. This issue affects Really Simple SSL: from n/a through 9.1.4. Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Cross Site Request Forgery.This issue affects Really Simple SSL: from n/a through <= 9.1.4.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 24 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Security Really Simple SSL allows Cross Site Request Forgery. This issue affects Really Simple SSL: from n/a through 9.1.4.
Title WordPress Really Simple Security plugin <= 9.1.4 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:17:23.337Z

Reserved: 2025-01-23T14:51:25.977Z

Link: CVE-2025-24623

cve-icon Vulnrichment

Updated: 2025-01-24T18:46:45.598Z

cve-icon NVD

Status : Deferred

Published: 2025-01-24T18:15:37.727

Modified: 2026-06-17T08:59:20.140

Link: CVE-2025-24623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:00:08Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)