CVE-2024-1076

T

he SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

Configurations

Configuration 1 (hide)

cpe:2.3:a:sslzen:ssl_zen:*:*:*:*:*:wordpress:*:*

History

17 Jun 2025, 18:53

Type Values Removed Values Added
First Time Sslzen
Sslzen ssl Zen
CPE cpe:2.3:a:sslzen:ssl_zen:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5/ - () https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5/ - Exploit, Third Party Advisory
CWE CWE-306

25 Mar 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

21 Nov 2024, 08:49

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5/ - () https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5/ -

30 Aug 2024, 13:15

Type Values Removed Values Added
Summary (en) The SSL Zen WordPress plugin before 4.6.0 only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX. (en) The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

08 May 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-08 06:15

Updated : 2025-06-17 18:53


NVD link : CVE-2024-1076

Mitre link : CVE-2024-1076

CVE.ORG link : CVE-2024-1076


JSON object : View

Products Affected
CWE
CWE-306

Missing Authentication for Critical Function