WP Vulnerability WatchVulnerability data as of September 27, 2026

Vulnerability alerts / September 25, 2026

Vulnerability in SSL Zen — SSL Certificate Installer & HTTPS Redirects — CVE-2026-17602

MediumSeverity
CVSS 4.9
0.6%Estimated exploit probability
EPSS
10,000+ sitesInstalls
4.7.43Fixed in

What to do now

Update SSL Zen — SSL Certificate Installer & HTTPS Redirects to 4.7.43 or later.

Affected versions

  • Everything up to and including 4.7.42

Affected: SSL Zen — SSL Certificate Installer & HTTPS Redirects (plugin, ssl-zen)

Check: The plugin on wordpress.org / Our record for SSL Zen — SSL Certificate Installer & HTTPS Redirects

What the vulnerability is

The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the 'file_name' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts