Sploitus

CVE-2024-1076

1 known exploit for CVE-2024-1076

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

Sslzen Ssl Zen
< 4.6.0
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.4% (34th percentile)
Weakness
CWE-306
NVD status
Analyzed
Published
2024-05-08
CVE-2024-1076 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-1076

Proof-of-concept code and exploit modules indexed by Sploitus