PT-2026-63791 · WordPress · Wp Encryption
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan versions prior to 7.8.6.7
Description
A Directory Traversal issue exists when the premium version of the software is enabled and active. Authenticated attackers with administrator-level access or higher can read arbitrary files on the server through the
imploded parameter, potentially exposing sensitive information. While the use of esc html() prevents direct PHP execution by encoding angle brackets, plaintext configuration files like .htaccess remain writable, allowing for redirect attacks or denial-of-service. Directory Traversal is a flaw that allows an attacker to access files and directories stored outside the web root folder.Recommendations
Update the plugin to version 7.8.6.7 or later.
Restrict access to the
imploded parameter to minimize the risk of exploitation.Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Encryption