Sensitive Information Exposure in WP Encryption SSL Plugin for WordPress
CVE-2023-7046

7.5HIGH

Summary

The One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress is affected by a vulnerability that allows unauthenticated attackers to gain access to sensitive data. The issue stems from exposed private key files, enabling the potential extraction of TLS Certificate Private Keys. Websites using versions up to and including 7.0 may be at risk, highlighting the importance of immediate action to secure these private keys.

Affected Version(s)

WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, Security+ * <= 7.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Zając
.