← All CVEs NewScan detects
medium

CVE-2026-81766

Really Simple Security missing capability check on plugin installation - a subsite admin installs arbitrary plugins from a supplied URL

Severity
medium
Affected product
really-simple-ssl
Affected versions
really-simple-ssl < 9.8.0
Fixed in
really-simple-ssl 9.8.0
Added to NewScan
2026-08-30
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints really-simple-ssl from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-30 (/daily-cve). Same generic slug->readme.txt version source as the row above; slug verified against api.wordpress.org (returns 'Really Simple Security - Simple and Performant Security (formerly Really Simple SSL)' at 9.8.0, i.e. the fix is published). Medium rather than high because the preconditions are real and narrow: multisite, a subsite administrator, and a network administrator who has enabled plugin management for subsites - given all three it is arbitrary plugin installation from a user-supplied URL, i.e. code execution. Version-match only: the confirming action would install a plugin on the target.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →