Data Modification Vulnerability in WP Encryption Plugin for WordPress
CVE-2026-3829

5.4MEDIUM

What is CVE-2026-3829?

The WP Encryption plugin for WordPress allows authenticated attackers with subscriber-level access and above to bypass crucial capability checks in the 'wple_basic_get_requests' function. This vulnerability affects all versions up to and including 7.8.5.10, enabling attackers to manipulate SSL-related configurations, including resetting the SSL setup state and altering plan selection options without the necessary permissions.

Affected Version(s)

WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan 0 <= 7.8.5.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kitch Global
.