PT-2024-16523 · WordPress+1 · Ssl Zen Wordpress Plugin+1
Krzysztof Zając
·
Published
2024-05-08
·
Updated
2025-06-17
·
CVE-2024-1076
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SSL Zen WordPress plugin versions prior to 4.6.0
Description
The issue arises because the SSL Zen WordPress plugin relies solely on .htaccess to prevent access to the site's generated private keys. This poses a problem for servers that do not support .htaccess files, such as NGINX, allowing an attacker to read the private keys.
Recommendations
For versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue. As a temporary workaround, consider configuring the server to restrict access to the private keys folder, or manually implementing an alternative method to prevent directory listing, until the update can be applied.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx
Ssl Zen Wordpress Plugin