Impact
Unauthenticated Broken Authentication allows an attacker to gain access to the WordPress site without credentials. This flaw is due to improper authentication checks in the Really Simple SSL plugin, enabling unauthorized users to log in and potentially manage the site. As a result, attackers may alter settings, compromise site security, or perform further attacks.
Affected Systems
The vulnerability affects the Really Simple SSL plugin provided by Really Simple Plugins, particularly all releases up to and including version 9.5.10. Any WordPress site that has an affected plugin installed is at risk.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while an EPSS score of less than 1% suggests the exploit is not widely observed yet, and the vulnerability is not listed in CISA KEV. The attack vector is likely via the web interface, where an attacker can submit crafted authentication requests without valid credentials.
OpenCVE Enrichment