PT-2026-83528 · WordPress · Really Simple Security

·

CVE-2026-81766

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Really Simple Security versions prior to 9.8.0
Description In WordPress Multisite environments, a privilege escalation flaw exists where the software fails to verify if a user has the necessary permissions before installing a plugin from a user-supplied URL. This allows a subsite administrator to bypass the security boundary and install and execute arbitrary PHP code within the network-shared plugin directory, a location normally reserved for the network administrator. Exploitation is possible only if the network administrator has enabled the Really Simple Security administration menu for subsites, which is not the default configuration.
Recommendations Update Really Simple Security to version 9.8.0 or later. Restrict network-level administrative capabilities to trusted accounts only.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81766

Affected Products

Really Simple Security