🔐 CVE Alert

CVE-2026-86781

MEDIUM 5.3

SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs.

Vendor unknown
Product ssl zen — ssl certificate installer & https redirects
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ssl zen — ssl certificate installer & https redirects

Be the first to know when new medium vulnerabilities affecting unknown ssl zen — ssl certificate installer & https redirects are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / SSL Zen — SSL Certificate Installer & HTTPS Redirects
0 < 4.7.40

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/858977f8-8ea3-4d3d-8967-31567f6786ff/

Credits

Suhayb Ahmed (cyboltx) WPScan