PT-2026-63791 · WordPress · Wp Encryption

·

CVE-2026-15786

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan versions prior to 7.8.6.7
Description A Directory Traversal issue exists when the premium version of the software is enabled and active. Authenticated attackers with administrator-level access or higher can read arbitrary files on the server through the imploded parameter, potentially exposing sensitive information. While the use of esc html() prevents direct PHP execution by encoding angle brackets, plaintext configuration files like .htaccess remain writable, allowing for redirect attacks or denial-of-service. Directory Traversal is a flaw that allows an attacker to access files and directories stored outside the web root folder.
Recommendations Update the plugin to version 7.8.6.7 or later. Restrict access to the imploded parameter to minimize the risk of exploitation.

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15786

Affected Products

Wp Encryption