CVE-2026-88798 UNKNOWN

CVE-2026-88798

Published: 2026-09-18

Description

The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…