Junglewise Threat Intelligence

CVE-2026-15786: GoWebSmarty WP Encryption directory traversal in imploded parameter

CVE-2026-15786 · Severity: medium · CVSS 4.9 · Published 2026-07-23

Executive brief

The WP Encryption plugin for WordPress, which helps websites manage SSL certificates and secure connections, contains a security flaw. An attacker with administrative access can exploit this to read sensitive server files or modify configuration files like .htaccess. This could lead to the exposure of private data or cause the website to become unavailable or redirect users to malicious sites.

Technical details

A directory traversal vulnerability exists in the WP Encryption plugin for WordPress due to insufficient validation of the 'imploded' parameter. Authenticated attackers with administrator-level privileges can exploit this to read arbitrary files on the server. Additionally, while PHP execution is mitigated by the use of esc_html() on file writes, attackers can still overwrite plaintext configuration files such as .htaccess. This allows for denial-of-service attacks or unauthorized URL redirection. The vulnerability affects all versions up to and including 7.8.6.6.

Affected products

  • GoWebSmarty WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan <= 7.8.6.6

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References