Description
The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: TLS Private Key Disclosure
Action: Patch
AI Analysis

Impact

The SSL Zen WordPress plugin before version 4.7.40 does not enforce capability or nonce verification on a certificate‑file download routine that runs early in the admin request lifecycle. As a result, any authenticated user, including those with only the Subscriber role, can download the site's TLS private key, certificates, and diagnostic logs, compromising the confidentiality of cryptographic materials and possibly enabling impersonation of the site.

Affected Systems

WordPress sites that use the SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin with a version older than 4.7.40 are affected. The vulnerability applies to environments where the plugin’s download endpoint is enabled during admin operations.

Risk and Exploitability

The flaw requires the attacker to be authenticated, but the lack of capability and nonce checks allows even low‑privileged Subscriber accounts to trigger the download. Once the private key or certificates are obtained, the attacker could decrypt traffic or forge communications, threatening confidentiality and integrity. The CVSS score of 5.3 indicates moderate severity, the EPSS score is unavailable, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation is straightforward for a user with legitimate site access and does not require additional network or local privilege escalation beyond the authenticated session.

Generated by OpenCVE AI on September 11, 2026 at 14:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SSL Zen to version 4.7.40 or later to fix the check failure.
  • If an upgrade is impossible, deactivate or uninstall the plugin to eliminate the vulnerable endpoint.
  • As a temporary measure, apply a patch or custom code to enforce capability and nonce checks for the certificate download routine so that only administrators can access it.

Generated by OpenCVE AI on September 11, 2026 at 14:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Unknown
Unknown ssl Zen — Ssl Certificate Installer & Https Redirects
Wordpress
Wordpress wordpress
Vendors & Products Unknown
Unknown ssl Zen — Ssl Certificate Installer & Https Redirects
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 11 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs.
Title SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure
References

Subscriptions

Unknown Ssl Zen — Ssl Certificate Installer & Https Redirects
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T10:00:47.722Z

Reserved: 2026-09-08T11:44:29.809Z

Link: CVE-2026-86781

cve-icon Vulnrichment

Updated: 2026-09-11T09:58:56.365Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:47.547

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-86781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:56:55Z

Weaknesses