CVE · Medium

CVE-2025-24623 — Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-24623 Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.2.0 Cross-Site Request Forgery (CSRF) Medium 4.3 < 9.2.0 9.2.0 2025-01-24

CVE-2025-24623

The Really Simple SSL plugin for WordPress contains a security flaw in versions up to 9.1.4, allowing malicious individuals to deceive administrators into taking unwanted actions by exploiting the plugin's failure to properly verify certain requests. This vulnerability stems from inadequate validation of specific function inputs. As a result, an attacker can potentially force an administrator to perform unintended actions without needing any prior authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.