PT-2026-40865 · Gowebsmarty+1 · Wp Encryption – One Click Free Ssl Certificate & Ssl / Https Redirect+1
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan versions prior to 7.8.5.11
Description
Unauthorized modification of data is possible due to missing capability checks in the
wple basic get requests() function. Authenticated attackers with subscriber level access or higher can reset the SSL setup state, force the SSL status to appear complete, and modify plan selection options.Recommendations
Update WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan to version 7.8.5.11 or later.
As a temporary workaround, restrict access to the
wple basic get requests() function to prevent unauthorized modifications.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Encryption – One Click Free Ssl Certificate & Ssl / Https Redirect
Wp-Letsencrypt-Ssl