Junglewise Threat Intelligence

CVE-2026-28569: SSL Zen cross-site scripting vulnerability

CVE-2026-28569 · Severity: high · CVSS 7.1 · Published 2026-08-18

Executive brief

SSL Zen is a WordPress plugin that manages SSL certificates and HTTPS configuration for websites. An unauthenticated attacker can inject malicious scripts into web pages viewed by site visitors, potentially stealing their data, compromising user accounts, or performing unauthorized actions on their behalf. No patch is currently available.

Technical details

This is a reflected cross-site scripting (XSS) vulnerability in SSL Zen versions 4.7.43 and earlier. The vulnerability is triggered when an unauthenticated attacker crafts a malicious link or request containing JavaScript code that the plugin fails to properly sanitize or escape. While the exploit requires a privileged user (such as a site administrator or logged-in user) to interact with the malicious link or submit a crafted form, the attacker does not need to authenticate. Successful exploitation allows arbitrary script execution in the victim's browser within the site context, enabling session hijacking, data theft, or unauthorized administrative actions. No official patch is available as of the advisory date (August 2026).

Affected products

  • SSL Zen SSL Zen <=4.7.43

Timeline

  • 2026-08-18: disclosed
  • 2026-01-14: reported

References