Vulnerabilities / WP Encryption / WPSEC-2026-0720

WP Encryption <= 7.8.8.1 - Missing Authorization to Unauthenticated SSL Domain Verification Continuation

Medium 5.3 CWE-862Fixed in 7.8.8.2
ID
WPSEC-2026-0720
Plugin
WP Encryption – One Click SSL / HTTPS & Free SSL Certificate, HTTPS Redirect, Security (wp-letsencrypt-ssl)
Affected
all versions before 7.8.8.2
Remediation
Update to 7.8.8.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
WP Encryption on WPSec AttackSurface
Fix released
Published

Description

The WP Encryption – One Click SSL / HTTPS & Free SSL Certificate, HTTPS Redirect, Security plugin for WordPress is vulnerable to unauthorized modification of data via the 'wpleauto' parameter in all versions up to, and including, 7.8.8.1, due to a missing capability check in the wple_auto_handler() function, which runs on admin_init. This makes it possible for unauthenticated attackers to start the Let's Encrypt domain verification and certificate generation flow with the site's saved settings. Doing so resets the order refresh state, overwrites the plugin's SSL stage, error, challenge and debug log data, and sends requests to the certificate authority.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0