Unrated severityNVD Advisory· Published Sep 18, 2026
CVE-2026-88798
CVE-2026-88798
Description
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <9.8.3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.