rootpwn

medium · CVSS v3 5.3 · EPSS 0.00145

CVE-2026-88798

The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using …

Description

The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
EPSS
0.00145

← All CVEs