CVE-2026-88798
Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofed Client IP Header
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.
| Vendor | unknown |
| Product | really simple security |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown really simple security
Be the first to know when new unknown vulnerabilities affecting unknown really simple security are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Really Simple Security
8.1.6 < 9.8.3
References
Credits
Naoki Kawahigashi WPScan