WordPress Plugin Vulnerabilities

SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure

Description

The plugin does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs.

Proof of Concept

Affects Plugins

Fixed in 4.7.40

References

Classification

Miscellaneous

Original Researcher
Suhayb Ahmed (cyboltx)
Submitter
Suhayb Ahmed (cyboltx)
Verified
Yes

Timeline

Publicly Published
2026-09-09 (about 2 days ago)
Added
2026-09-09 (about 1 day ago)
Last Updated
2026-09-09 (about 1 day ago)

Other