Junglewise Threat Intelligence

CVE-2026-3829: WP Encryption WordPress plugin missing authorization in wple_basic_get_requests

CVE-2026-3829 · Severity: medium · CVSS 5.4 · Published 2026-05-14

Executive brief

A vulnerability in the WP Encryption plugin for WordPress allows low-level users, such as subscribers, to interfere with the website's security settings. An attacker could reset the SSL certificate setup process or manipulate subscription plan options. This could lead to service disruptions or administrative confusion regarding the site's encryption status.

Technical details

The vulnerability is classified as Missing Authorization (CWE-862) within the 'wple_basic_get_requests' function of the WP Encryption plugin. Because the function lacks proper capability checks, any authenticated user with at least subscriber-level permissions can trigger administrative actions via network requests. Specifically, an attacker can reset the SSL setup state, bypass completion checks to make SSL appear fully configured when it is not, and modify internal plan selection options. The issue is resolved in version 7.8.5.11.

Affected products

  • WP Encryption WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan Up to, and including, 7.8.5.10

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory

References