PT-2026-40865 · Gowebsmarty+1 · Wp Encryption – One Click Free Ssl Certificate & Ssl / Https Redirect+1

·

CVE-2026-3829

·

Published

2026-05-13

·

Updated

2026-05-14

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan versions prior to 7.8.5.11
Description Unauthorized modification of data is possible due to missing capability checks in the wple basic get requests() function. Authenticated attackers with subscriber level access or higher can reset the SSL setup state, force the SSL status to appear complete, and modify plan selection options.
Recommendations Update WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan to version 7.8.5.11 or later. As a temporary workaround, restrict access to the wple basic get requests() function to prevent unauthorized modifications.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3829

Affected Products

Wp Encryption – One Click Free Ssl Certificate & Ssl / Https Redirect
Wp-Letsencrypt-Ssl