PT-2026-98383 · WordPress · Ssl Zen

·

CVE-2026-17577

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SSL Zen plugin for WordPress versions prior to 4.7.43
Description Reflected Cross-Site Scripting occurs when unauthenticated attackers trick users into clicking specially crafted links to inject arbitrary web scripts. The issue exists because the ssl zen messages::getMessages() function constructs the 'token missmatch' message by decoding the uri and host parameters using base64 decode(). Since sanitize text field() cannot detect malicious scripts hidden within base64-encoded data, the decoded raw HTML is subsequently echoed unescaped by the showMessage() function.
Recommendations Update the plugin to a version newer than 4.7.42. As a temporary mitigation, restrict or avoid the use of the uri and host parameters until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17577

Affected Products

Ssl Zen