CyberRota Analysis
AI-GeneratedThe SSL Zen plugin for WordPress prior to version 4.7.40 is vulnerable due to inadequate capability and nonce checks, enabling any authenticated user, including those with low-level permissions like Subscribers, to download sensitive TLS private keys, certificates, and diagnostic logs. This exposure could lead to unauthorized access to secure communications and compromise the integrity of the website. WordPress administrators and site owners using this plugin should prioritize immediate updates to mitigate potential security risks.
Original NVD Description
The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs.