WP Encryption <= 7.8.8.1 - Missing Authorization to Unauthenticated SSL Domain Verification Continuation
- ID
- WPSEC-2026-0720
- Plugin
- WP Encryption – One Click SSL / HTTPS & Free SSL Certificate, HTTPS Redirect, Security (wp-letsencrypt-ssl)
- Affected
- all versions before 7.8.8.2
- Remediation
- Update to 7.8.8.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- WP Encryption on WPSec AttackSurface
- Fix released
- Published
Description
The WP Encryption – One Click SSL / HTTPS & Free SSL Certificate, HTTPS Redirect, Security plugin for WordPress is vulnerable to unauthorized modification of data via the 'wpleauto' parameter in all versions up to, and including, 7.8.8.1, due to a missing capability check in the wple_auto_handler() function, which runs on admin_init. This makes it possible for unauthenticated attackers to start the Let's Encrypt domain verification and certificate generation flow with the site's saved settings. Doing so resets the order refresh state, overwrites the plugin's SSL stage, error, challenge and debug log data, and sends requests to the certificate authority.
References
- https://wpsec.com/vuln/WPSEC-2026-0720/
- https://plugins.svn.wordpress.org/wp-letsencrypt-ssl/tags/7.8.8.2/
- https://wordpress.org/plugins/wp-letsencrypt-ssl/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS