Sensitive Information Exposure in WP Encryption SSL Plugin for WordPress
CVE-2023-7046
7.5HIGH
Key Information:
- Vendor
Wordpress
- Status
- Vendor
- CVE Published:
- 9 April 2024
What is CVE-2023-7046?
The One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress is affected by a vulnerability that allows unauthenticated attackers to gain access to sensitive data. The issue stems from exposed private key files, enabling the potential extraction of TLS Certificate Private Keys. Websites using versions up to and including 7.0 may be at risk, highlighting the importance of immediate action to secure these private keys.
Affected Version(s)
WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, Security+ * <= 7.0