🔐 CVE Alert

CVE-2026-15786

MEDIUM 4.9

WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Write via 'imploded' Parameter

CVSS Score
4.9
EPSS Score
0.0%
EPSS Percentile
0th

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Although file write content is passed through esc_html(), which encodes angle brackets and prevents direct PHP execution, plaintext configuration files such as .htaccess are fully writable and exploitable for denial-of-service or redirect attacks.

CWE CWE-22
Vendor gowebsmarty
Product wp encryption – lifetime free ssl cert & https, force ssl / https redirect, ssl security
Published Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for gowebsmarty wp encryption – lifetime free ssl cert & https, force ssl / https redirect, ssl security

Be the first to know when new medium vulnerabilities affecting gowebsmarty wp encryption – lifetime free ssl cert & https, force ssl / https redirect, ssl security are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

gowebsmarty / WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security
0 ≤ 7.8.6.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/3ee86d33-5a1e-4dc5-b2f6-0beffd8a6b2e?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-letsencrypt-ssl/tags/7.8.6.6/admin/le_admin.php#L2138 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-letsencrypt-ssl/tags/7.8.6.6/admin/le_admin.php#L2120 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-letsencrypt-ssl/tags/7.8.6.6/admin/le_admin.php#L150 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?reponame=&old=3617401%40wp-letsencrypt-ssl&new=3617401%40wp-letsencrypt-ssl

Credits

Wordfence PRISM