CVE-2026-81766
Really Simple Security missing capability check on plugin installation - a subsite admin installs arbitrary plugins from a supplied URL
- Severity
- medium
- Affected product
- really-simple-ssl
- Affected versions
- really-simple-ssl < 9.8.0
- Fixed in
- really-simple-ssl 9.8.0
- Added to NewScan
- 2026-08-30
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints really-simple-ssl from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-30 (/daily-cve). Same generic slug->readme.txt version source as the row above; slug verified against api.wordpress.org (returns 'Really Simple Security - Simple and Performant Security (formerly Really Simple SSL)' at 9.8.0, i.e. the fix is published). Medium rather than high because the preconditions are real and narrow: multisite, a subsite administrator, and a network administrator who has enabled plugin management for subsites - given all three it is arbitrary plugin installation from a user-supplied URL, i.e. code execution. Version-match only: the confirming action would install a plugin on the target.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →