Impact
The Really Simple Security plugin for WordPress does not validate a client‑supplied address value before using it as an options key, allowing an unauthenticated user to repeatedly create new keys of arbitrary length. This uncontrolled growth of the options table leads to significant memory usage and degraded performance, effectively causing a denial of service. The weakness aligns with CWE‑400, Uncontrolled Resource Consumption.
Affected Systems
The vulnerability affects the Really Simple Security WordPress plugin versions prior to 9.8.3. Any WordPress installation running v9.8.2 or earlier is susceptible. The issue is limited to the plugin’s options handling logic and does not involve other WordPress core components.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, and the EPSS score of less than 1% shows a low probability of exploitation in the wild. The defect is not listed in the CISA KEV catalog. Attackers can exploit it remotely by sending crafted HTTP requests containing a spoofed client IP header, bypassing authentication checks. Once triggered, the unbounded option growth persists, causing sustained performance degradation until the database or the plugin state is cleaned up or the vulnerability is patched.
OpenCVE Enrichment