PT-2026-83528 · WordPress · Really Simple Security
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Really Simple Security versions prior to 9.8.0
Description
In WordPress Multisite environments, a privilege escalation flaw exists where the software fails to verify if a user has the necessary permissions before installing a plugin from a user-supplied URL. This allows a subsite administrator to bypass the security boundary and install and execute arbitrary PHP code within the network-shared plugin directory, a location normally reserved for the network administrator. Exploitation is possible only if the network administrator has enabled the Really Simple Security administration menu for subsites, which is not the default configuration.
Recommendations
Update Really Simple Security to version 9.8.0 or later.
Restrict network-level administrative capabilities to trusted accounts only.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Really Simple Security