Data Modification Vulnerability in WP Encryption Plugin for WordPress
CVE-2026-3829
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 May 2026
What is CVE-2026-3829?
The WP Encryption plugin for WordPress allows authenticated attackers with subscriber-level access and above to bypass crucial capability checks in the 'wple_basic_get_requests' function. This vulnerability affects all versions up to and including 7.8.5.10, enabling attackers to manipulate SSL-related configurations, including resetting the SSL setup state and altering plan selection options without the necessary permissions.
Affected Version(s)
WP Encryption β One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan 0 <= 7.8.5.10