Description
The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the 'file_name' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Published: 2026-09-25
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Read via Directory Traversal by Administrator+
Action: Apply Patch
AI Analysis

Impact

The SSL Zen plugin for WordPress allows an attacker with administrator or higher privileges to inject a crafted "file_name" parameter that bypasses the intended file boundary checks. This results in the server returning the contents of any file on the local filesystem, exposing potentially sensitive data such as configuration files, passwords, or private keys. The primary consequence is the loss of confidentiality for any readable file, while integrity and availability are not directly impacted by the flaw. Affected systems include the SSL Zen plugin (sslzen) up to and including version 4.7.42. Any WordPress installation deploying any of these affected releases is vulnerable unless the plugin is upgraded or removed. According to the available metrics, the CVSS base score is 4.9, indicating a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with administrator or higher rights, so the attack surface is limited to users who already have privilege. Nonetheless, once an attacker gains such privileges, they can read arbitrary files, providing valuable information that may aid further attacks.

Affected Systems

The vulnerability impacts the SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin from sslzen, for all releases up to and including version 4.7.42. Any WordPress site that has installed any of these versions is potentially affected.

Risk and Exploitability

The flaw carries a CVSS score of 4.9, a moderate severity rating. No EPSS score is currently available, and the issue has not been catalogued as a Known Exploited Vulnerability by CISA. Attackers must possess administrator or higher-level authentication to exploit the path traversal, but once this privilege is in place they can read arbitrary files from the server. The lack of a public exploit does not mitigate the risk for privileged administrators, who have a direct attack route to obtain sensitive data.

Generated by OpenCVE AI on September 25, 2026 at 09:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SSL Zen to version 4.7.43 or later, which removes the directory traversal flaw.
  • If an upgrade is not possible immediately, restrict file system permissions on the WordPress root and plugin directories so that read access is limited to the web server user and prevent arbitrary file exposure.
  • Consider deactivating or uninstalling SSL Zen if it is not essential, as a temporary measure to eliminate the vulnerable code path.

Generated by OpenCVE AI on September 25, 2026 at 09:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Sslzen
Sslzen ssl Zen
Wordpress-extensions
Wordpress-extensions ssl Zen
Vendors & Products Sslzen
Sslzen ssl Zen
Wordpress-extensions
Wordpress-extensions ssl Zen

Fri, 25 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the 'file_name' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Title SSL Zen <= 4.7.42 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'file_name' Parameter
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Sslzen Ssl Zen
Wordpress-extensions Ssl Zen
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-25T13:00:14.914Z

Reserved: 2026-07-27T16:30:48.671Z

Link: CVE-2026-17602

cve-icon Vulnrichment

Updated: 2026-09-25T12:55:52.147Z

cve-icon NVD

Status : Deferred

Published: 2026-09-25T08:16:40.247

Modified: 2026-09-25T14:17:18.233

Link: CVE-2026-17602

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T14:14:29Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')