{"id":"CVE-2026-17602","title":"The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the 'file_name' parameter parameter","summary":"The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the 'file_name' parameter parameter. This makes it possible for authenti…","severity":"medium","cvss":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-22"],"vendor":"sslzen","product":"SSL Zen — SSL Certificate Installer & HTTPS Redirects","affected":["ssl_zen_ssl_certificate_installer_https_redirects <= 4.7.42"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T13:08:08.163","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-17602","references":[{"url":"https://plugins.trac.wordpress.org/browser/ssl-zen/tags/4.7.12/ssl_zen/classes/class.ssl_zen_admin.php#L492","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ssl-zen/tags/4.7.12/ssl_zen/classes/class.ssl_zen_admin.php#L496","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ssl-zen/tags/4.7.12/ssl_zen/classes/class.ssl_zen_admin.php#L54","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ssl-zen/tags/4.7.42/ssl_zen/classes/class.ssl_zen_admin.php#L492","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ssl-zen/tags/4.7.42/ssl_zen/classes/class.ssl_zen_admin.php#L496","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ssl-zen/tags/4.7.42/ssl_zen/classes/class.ssl_zen_admin.php#L54","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3701590%40ssl-zen&new=3701590%40ssl-zen","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6bf4cc39-3a26-462d-a540-2d53e53dfa66?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T08:01:56.743Z","slug":"CVE-2026-17602","body":"## Overview\n\nThe SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the 'file_name' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":27,"depthScoreParts":{"impact":27,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}