Description
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Although file write content is passed through esc_html(), which encodes angle brackets and prevents direct PHP execution, plaintext configuration files such as .htaccess are fully writable and exploitable for denial-of-service or redirect attacks. This is only exploitable when the premium version of the software is enabled and active.
Published: 2026-07-23
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Encryption plugin for WordPress suffers from a Directory Traversal flaw in the 'imploded' parameter that allows authenticated users with administrator privileges or higher to read the contents of arbitrary files on the server. Even though file write content is encoded, the plugin still permits the fully writable modification of plaintext configuration files such as .htaccess. In practice this means an attacker could manipulate .htaccess entries to cause denial‑of‑service or redirect attacks, or otherwise compromise site functionality.

Affected Systems

The vulnerability affects GoWebSmarty’s WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security plugin for WordPress. Versions up to and including 7.8.6.6 are present, with the flaw only exploitable when the premium version is enabled and active.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.4 and an EPSS score of less than 1%, and it is not currently listed in the CISA KEV catalog. As it requires administrator‑level authentication and the premium mode to be active, the practical attack surface is limited to sites with that configuration. Based on the lack of publicly reported exploits, it is inferred that no exploitation has been publicly documented, but the low EPSS indicates a low probability of exploitation. Nevertheless, the ability to tamper with .htaccess remains a potential threat.

Generated by OpenCVE AI on August 3, 2026 at 22:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Encryption plugin to the latest version, where the vulnerability has been fixed.
  • If the premium functionality is not required, disable the premium mode or uninstall the plugin.
  • Limit the number of administrator accounts and enforce strict role‑based access controls to reduce the likelihood that an attacker can gain the necessary privileges.

Generated by OpenCVE AI on August 3, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Although file write content is passed through esc_html(), which encodes angle brackets and prevents direct PHP execution, plaintext configuration files such as .htaccess are fully writable and exploitable for denial-of-service or redirect attacks. The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Although file write content is passed through esc_html(), which encodes angle brackets and prevents direct PHP execution, plaintext configuration files such as .htaccess are fully writable and exploitable for denial-of-service or redirect attacks. This is only exploitable when the premium version of the software is enabled and active.
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Gowebsmarty
Gowebsmarty wp Encryption – Lifetime Free Ssl Cert & Https, Force Ssl / Https Redirect, Ssl Security
Wordpress
Wordpress wordpress
Vendors & Products Gowebsmarty
Gowebsmarty wp Encryption – Lifetime Free Ssl Cert & Https, Force Ssl / Https Redirect, Ssl Security
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Description The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Although file write content is passed through esc_html(), which encodes angle brackets and prevents direct PHP execution, plaintext configuration files such as .htaccess are fully writable and exploitable for denial-of-service or redirect attacks.
Title WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Write via 'imploded' Parameter
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Gowebsmarty Wp Encryption – Lifetime Free Ssl Cert & Https, Force Ssl / Https Redirect, Ssl Security
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-24T22:39:47.800Z

Reserved: 2026-07-14T19:18:05.209Z

Link: CVE-2026-15786

cve-icon Vulnrichment

Updated: 2026-07-23T13:37:45.643Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T10:16:51.207

Modified: 2026-07-24T23:16:50.087

Link: CVE-2026-15786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:45:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')