Impact
The WP Encryption plugin for WordPress suffers from a Directory Traversal flaw in the 'imploded' parameter that allows authenticated users with administrator privileges or higher to read the contents of arbitrary files on the server. Even though file write content is encoded, the plugin still permits the fully writable modification of plaintext configuration files such as .htaccess. In practice this means an attacker could manipulate .htaccess entries to cause denial‑of‑service or redirect attacks, or otherwise compromise site functionality.
Affected Systems
The vulnerability affects GoWebSmarty’s WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security plugin for WordPress. Versions up to and including 7.8.6.6 are present, with the flaw only exploitable when the premium version is enabled and active.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.4 and an EPSS score of less than 1%, and it is not currently listed in the CISA KEV catalog. As it requires administrator‑level authentication and the premium mode to be active, the practical attack surface is limited to sites with that configuration. Based on the lack of publicly reported exploits, it is inferred that no exploitation has been publicly documented, but the low EPSS indicates a low probability of exploitation. Nevertheless, the ability to tamper with .htaccess remains a potential threat.
OpenCVE Enrichment