PT-2024-3318 · WordPress · Wp Encryption

Krzysztof Zając

·

Published

2024-04-09

·

Updated

2024-04-10

·

CVE-2023-7046

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Encryption plugin for WordPress versions up to, and including, 7.0
Description The issue is related to insufficient protection of internal data, which can be exploited by a remote attacker to disclose protected information. Specifically, the vulnerability allows unauthenticated attackers to extract sensitive data, including TLS Certificate Private Keys, due to exposed Private key files.
Recommendations For WP Encryption plugin for WordPress versions up to, and including, 7.0, update to a version later than 7.0 to resolve the issue. As a temporary workaround, consider restricting access to the Private key files to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-03558
CVE-2023-7046

Affected Products

Wp Encryption