CVE-2026-86781 PUBLISHED

SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure

Assigner: WPScan
Reserved: 08.09.2026 Published: 11.09.2026 Updated: 11.09.2026

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs.

Product Status

Vendor Unknown
Product SSL Zen — SSL Certificate Installer & HTTPS Redirects
Versions Default: unaffected
  • affected from 0 to 4.7.40 (excl.)

Credits

  • Suhayb Ahmed (cyboltx) finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE