CVE-2026-88798
EUVD-2026-8267618.09.2026, 06:16
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.