← WordPress Vulnerabilities
WordPress security by component

SSL Zen — SSL Certificate Installer & HTTPS Redirects

SSL Zen — SSL Certificate Installer & HTTPS Redirects (ssl-zen-ssl-certificate-installer-https-redirects) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.3.

Plugin slug: ssl-zen-ssl-certificate-installer-https-redirects

CVE-2026-86781: SSL Zen exposes TLS private keys to subscribers

SSL Zen before 4.7.40 runs a certificate-file download routine early in the WordPress admin request lifecycle without a capability or nonce check. Any authenticated user, including a Subscriber, can download the site's TLS private key, certificates, and diagnostic logs. The authoritative export does not name the request action, file parameter, or download function.

PublishedSep 11, 2026
Known safe version4.7.40
Published vulnerabilities for ssl-zen-ssl-certificate-installer-https-redirects
Safe version
Sep 11, 2026 CVE-2026-86781
SSL Zen exposes TLS private keys to subscribers
SSL Zen before 4.7.40 runs a certificate-file download routine early in the WordPress admin request lifecycle without a capability or nonce check. Any authenticated user, including a Subscriber, can download the site's TLS private key, certificates, and diagnostic logs. The authoritative export does not name the request action, file parameter, or download function.
4.7.40
CVE5.3
NVDPending