WordPress security by component
SSL Zen — SSL Certificate Installer & HTTPS Redirects
SSL Zen — SSL Certificate Installer & HTTPS Redirects (ssl-zen-ssl-certificate-installer-https-redirects) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.3.
Plugin slug:
ssl-zen-ssl-certificate-installer-https-redirectsLatest vulnerability
CVE-2026-86781: SSL Zen exposes TLS private keys to subscribers
SSL Zen before 4.7.40 runs a certificate-file download routine early in the WordPress admin request lifecycle without a capability or nonce check. Any authenticated user, including a Subscriber, can download the site's TLS private key, certificates, and diagnostic logs. The authoritative export does not name the request action, file parameter, or download function.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-86781
SSL Zen exposes TLS private keys to subscribers
SSL Zen before 4.7.40 runs a certificate-file download routine early in the WordPress admin request lifecycle without a capability or nonce check. Any authenticated user, including a Subscriber, can download the site's TLS private key, certificates, and diagnostic logs. The authoritative export does not name the request action, file parameter, or download function.
|
4.7.40 |
CVE5.3
NVDPending
|