The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.
History

Tue, 25 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Aug 2024 13:15:00 +0000

Type Values Removed Values Added
Description The SSL Zen WordPress plugin before 4.6.0 only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX. The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-05-08T06:00:02.175Z

Updated: 2025-03-25T19:06:42.370Z

Reserved: 2024-01-30T16:33:37.347Z

Link: CVE-2024-1076

cve-icon Vulnrichment

Updated: 2024-08-01T18:26:30.496Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-08T06:15:06.877

Modified: 2025-03-25T20:15:20.853

Link: CVE-2024-1076

cve-icon Redhat

No data.