Impact
Unauthenticated inputs to the Really Simple SSL plugin can lead to a denial of service condition on WordPress sites, as described in CWE-770. Attackers can trigger resource exhaustion without needing user credentials, interrupting site availability.
Affected Systems
WordPress instances that run the Really Simple SSL plugin version 9.8.0 or earlier are affected. The plugin, developed by Really Simple Plugins, can be found in the WordPress plugin repository under the name "Really Simple SSL".
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. No EPSS score is published, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. An attacker can exploit the flaw from any internet‑connected location with access to the site, making it unauthenticated. The lack of availability of exploit code and the moderate score mean that while the risk exists, immediate exploitation is less likely without deliberate targeting.
OpenCVE Enrichment