CVE-2024-1076

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sslzen:ssl_zen:*:*:*:*:*:wordpress:*:*

History

17 Jun 2025, 18:53

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5/ - () https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5/ - Exploit, Third Party Advisory
CWE CWE-306
CPE cpe:2.3:a:sslzen:ssl_zen:*:*:*:*:*:wordpress:*:*
First Time Sslzen ssl Zen
Sslzen

25 Mar 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

Information

Published : 2024-05-08 06:15

Updated : 2025-06-17 18:53


NVD link : CVE-2024-1076

Mitre link : CVE-2024-1076

CVE.ORG link : CVE-2024-1076


JSON object : View

Products Affected

sslzen

  • ssl_zen
CWE
CWE-306

Missing Authentication for Critical Function