Impact
The SSL Zen WordPress plugin before version 4.7.40 does not enforce capability or nonce verification on a certificate‑file download routine that runs early in the admin request lifecycle. As a result, any authenticated user, including those with only the Subscriber role, can download the site's TLS private key, certificates, and diagnostic logs, compromising the confidentiality of cryptographic materials and possibly enabling impersonation of the site.
Affected Systems
WordPress sites that use the SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin with a version older than 4.7.40 are affected. The vulnerability applies to environments where the plugin’s download endpoint is enabled during admin operations.
Risk and Exploitability
The flaw requires the attacker to be authenticated, but the lack of capability and nonce checks allows even low‑privileged Subscriber accounts to trigger the download. Once the private key or certificates are obtained, the attacker could decrypt traffic or forge communications, threatening confidentiality and integrity. The CVSS score of 5.3 indicates moderate severity, the EPSS score is unavailable, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation is straightforward for a user with legitimate site access and does not require additional network or local privilege escalation beyond the authenticated session.
OpenCVE Enrichment