Description
The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'host' parameter in all versions up to, and including, 4.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is only exploitable when in the system_requirements stage.
Published: 2026-09-19
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client-side XSS
Action: Immediate Patch
AI Analysis

Impact

The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress contains an input validation flaw that allows an unauthenticated attacker to inject arbitrary JavaScript payloads through the 'host' parameter during the system_requirements stage. When a user follows a malicious URL containing an unsanitized 'host' value, the attacker‑supplied code is reflected and executed in the victim’s browser. This represents a Reflected Cross‑Site Scripting (CWE‑79) weakness that can enable attackers to run client‑side code in the context of any user who clicks the link. The impact is confined to the client side and does not affect the server or internal plugin data.

Affected Systems

The vulnerability affects the SSL Zen WordPress plugin, version 4.7.42 and earlier. All builds up to and including 4.7.42 are impacted.

Risk and Exploitability

The CVSS v3 score of 6.1 indicates moderate severity. The EPSS score of < 1 % shows a very low probability of exploitation at the time of the analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation can occur if an attacker crafts a URL with a malicious 'host' parameter and a user clicks it while the plugin is in the system_requirements stage; therefore the attack vector relies on user interaction and is limited to client browsers.

Generated by OpenCVE AI on September 19, 2026 at 23:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the SSL Zen plugin to version 4.7.43 or later.
  • If an upgrade is not immediately possible, disable the system_requirements feature or restrict access to that page so the 'host' parameter cannot be processed.
  • Implement a content security policy that disallows inline script execution to reduce the impact of any reflected XSS.

Generated by OpenCVE AI on September 19, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Sslzen
Sslzen ssl Zen
Wordpress-extensions
Wordpress-extensions ssl Zen
Vendors & Products Sslzen
Sslzen ssl Zen
Wordpress-extensions
Wordpress-extensions ssl Zen

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'host' parameter in all versions up to, and including, 4.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is only exploitable when in the system_requirements stage.
Title SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' and 'host' Parameters
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Sslzen Ssl Zen
Wordpress-extensions Ssl Zen
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:23.380Z

Reserved: 2026-07-10T20:16:25.137Z

Link: CVE-2026-15463

cve-icon Vulnrichment

Updated: 2026-09-19T13:53:08.671Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:52.627

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-15463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')