The SSL Zen WordPress plugin before 4.6.0 only relies on...
Moderate severity
Unreviewed
Published
May 8, 2024
to the GitHub Advisory Database
•
Updated Jun 17, 2025
Description
Published by the National Vulnerability Database
May 8, 2024
Published to the GitHub Advisory Database
May 8, 2024
Last updated
Jun 17, 2025
The SSL Zen WordPress plugin before 4.6.0 only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.
References