CVE-2026-88798 PUBLISHED

Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofed Client IP Header

Assigner: WPScan
Reserved: 10.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.

Product Status

Vendor Unknown
Product Really Simple Security
Versions Default: unaffected
  • affected from 8.1.6 to 9.8.3 (excl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE