Description
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The Really Simple Security plugin for WordPress does not validate a client‑supplied address value before using it as an options key, allowing an unauthenticated user to repeatedly create new keys of arbitrary length. This uncontrolled growth of the options table leads to significant memory usage and degraded performance, effectively causing a denial of service. The weakness aligns with CWE‑400, Uncontrolled Resource Consumption.

Affected Systems

The vulnerability affects the Really Simple Security WordPress plugin versions prior to 9.8.3. Any WordPress installation running v9.8.2 or earlier is susceptible. The issue is limited to the plugin’s options handling logic and does not involve other WordPress core components.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, and the EPSS score of less than 1% shows a low probability of exploitation in the wild. The defect is not listed in the CISA KEV catalog. Attackers can exploit it remotely by sending crafted HTTP requests containing a spoofed client IP header, bypassing authentication checks. Once triggered, the unbounded option growth persists, causing sustained performance degradation until the database or the plugin state is cleaned up or the vulnerability is patched.

Generated by OpenCVE AI on September 19, 2026 at 19:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Really Simple Security to version 9.8.3 or later to receive the fix that validates client IP addresses before using them as storage keys.
  • If an update is not immediately possible, block or sanitize spoofed client IP headers before they reach the plugin logic, for example by configuring a web application firewall or edge filtering rule.
  • Monitor the WordPress options table and server resource usage for abnormal growth patterns, and clean up or prune excessively large options entries to restore normal performance.

Generated by OpenCVE AI on September 19, 2026 at 19:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Really-simple-plugins
Really-simple-plugins really Simple Security
Wordpress
Wordpress wordpress
Vendors & Products Really-simple-plugins
Really-simple-plugins really Simple Security
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.
Title Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofed Client IP Header
References

Subscriptions

Really-simple-plugins Really Simple Security
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:09:13.043Z

Reserved: 2026-09-10T08:22:07.339Z

Link: CVE-2026-88798

cve-icon Vulnrichment

Updated: 2026-09-18T11:02:13.271Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:41.053

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-88798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:30:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption