CVE-2026-86781
SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs.
| Vendor | unknown |
| Product | ssl zen — ssl certificate installer & https redirects |
| Published | Sep 11, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ssl zen — ssl certificate installer & https redirects
Be the first to know when new medium vulnerabilities affecting unknown ssl zen — ssl certificate installer & https redirects are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / SSL Zen — SSL Certificate Installer & HTTPS Redirects
0 < 4.7.40
References
Credits
Suhayb Ahmed (cyboltx) WPScan