Impact
The vulnerability exists in the Really Simple SSL WordPress plugin versions 9.8.0 and earlier. It is a broken authentication flaw (CWE‑288) that lets an attacker bypass the two‑factor authentication step, granting unauthenticated access to the WordPress admin area. With that access an attacker can execute any privileged action, including modifying site content, exfiltrating data, or installing malware.
Affected Systems
All WordPress sites that have the Really Simple SSL plugin from Really Simple Plugins installed with a version 9.8.0 or older are affected. The flaw specifically impacts installations that rely on the plugin to enforce two‑factor authentication.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. No EPSS score is available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attacker can execute the exploit via a remote web request without any authentication.
OpenCVE Enrichment