← Späť na vyhľadávanie CVE

CVE-2026-15786

WP Encryption

Popis

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the -imploded- parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Although file write content is passed through esc_html(), which encodes angle brackets and prevents direct PHP execution, plaintext configuration files such as .htaccess are fully writable and exploitable for denial-of-service or redirect attacks. This is only exploitable when the premium version of the software is enabled and active.

CVSS 4.4EPSS 0.41000000000000003%Riziko 0.46
Zobraziť zdroj
Zverejnené
2026-07-23 10:16:51
Dotknuté verzie
<=7.8.6.6
Typ
Webová aplikácia
Posledná úprava
2026-07-24 23:16:50
Vektor
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N