CVE-2024-1076

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sslzen:ssl_zen:*:*:*:*:*:wordpress:*:*

History

17 Jun 2025, 18:53

Type Values Removed Values Added
First Time Sslzen
Sslzen ssl Zen
References () https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5/ - () https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:sslzen:ssl_zen:*:*:*:*:*:wordpress:*:*
CWE CWE-306

25 Mar 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

21 Nov 2024, 08:49

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5/ - () https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5/ -

30 Aug 2024, 13:15

Type Values Removed Values Added
Summary (en) The SSL Zen WordPress plugin before 4.6.0 only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX. (en) The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

08 May 2024, 13:15

Type Values Removed Values Added
Summary
  • (es) El complemento SSL Zen WordPress anterior a 4.6.0 solo se basa en el uso de .htaccess para evitar que los visitantes accedan a las claves privadas generadas por el sitio, lo que permite a un atacante leerlas si el sitio se ejecuta en un servidor que no admite archivos .htaccess, como NGINX.

08 May 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-08 06:15

Updated : 2025-06-17 18:53


NVD link : CVE-2024-1076

Mitre link : CVE-2024-1076

CVE.ORG link : CVE-2024-1076


JSON object : View

Products Affected

sslzen

  • ssl_zen
CWE
CWE-306

Missing Authentication for Critical Function