← Voltar à pesquisa de CVEs

CVE-2026-15786

WP Encryption

Descrição

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the -imploded- parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Although file write content is passed through esc_html(), which encodes angle brackets and prevents direct PHP execution, plaintext configuration files such as .htaccess are fully writable and exploitable for denial-of-service or redirect attacks. This is only exploitable when the premium version of the software is enabled and active.

CVSS 4.4EPSS 0.41000000000000003%Risco 0.46
Ver fonte
Publicação
2026-07-23 10:16:51
Versões afetadas
<=7.8.6.6
Tipo
Aplicação web
Última alteração
2026-07-24 23:16:50
Vetor
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N