Impact
The SSL Zen plugin for WordPress allows an attacker with administrator or higher privileges to inject a crafted "file_name" parameter that bypasses the intended file boundary checks. This results in the server returning the contents of any file on the local filesystem, exposing potentially sensitive data such as configuration files, passwords, or private keys. The primary consequence is the loss of confidentiality for any readable file, while integrity and availability are not directly impacted by the flaw. Affected systems include the SSL Zen plugin (sslzen) up to and including version 4.7.42. Any WordPress installation deploying any of these affected releases is vulnerable unless the plugin is upgraded or removed. According to the available metrics, the CVSS base score is 4.9, indicating a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with administrator or higher rights, so the attack surface is limited to users who already have privilege. Nonetheless, once an attacker gains such privileges, they can read arbitrary files, providing valuable information that may aid further attacks.
Affected Systems
The vulnerability impacts the SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin from sslzen, for all releases up to and including version 4.7.42. Any WordPress site that has installed any of these versions is potentially affected.
Risk and Exploitability
The flaw carries a CVSS score of 4.9, a moderate severity rating. No EPSS score is currently available, and the issue has not been catalogued as a Known Exploited Vulnerability by CISA. Attackers must possess administrator or higher-level authentication to exploit the path traversal, but once this privilege is in place they can read arbitrary files from the server. The lack of a public exploit does not mitigate the risk for privileged administrators, who have a direct attack route to obtain sensitive data.
OpenCVE Enrichment